Skip to main content

Single-Tenant (March 2023)

New features and improvements

Status

Description

Version 2.80.02 (Released on March 5, 2023)

NEW

The SAST engine version in Checkmarx One has been upgraded to 9.5.3. For details, please refer to Release Notes for Engine Pack 9.5.3.

NEW

This version introduces Policy Management, the ability to define, manage, and track your organization’s security policies. The detailed description of this feature is available at Overview.

NEW

The user can now compare any two scans from the same project that was ran with the SAST engine. The comparison shows which results were fixed, which are new and recurrent between both scans. For better visibility, the scans are shown in side by side screens:

Compare_Fixed.png

NEW

Checkmarx One now allows scanning repositories that contain up to 9.5M lines of code and retrieving scan results within a reasonable time.

CLI and Plugins Release of March 2023

Version 2.0.43

Status

Item

Description

UPDATED

Tags and Groups

When tags and/or groups are specified in the scan create command, those values now override the tags and groups that were previously assigned to the project.

FIXED

Thresholds

Fixed issue that spaces and capital letters had been interfering with Threshold functionality.

FIXED

Scan summary

Fixed issue that SCA vulnerabilities marked as "Not Exploitable" were being included in the scan summary data. (Current behavior for all scanners is that "Not Exploitable" vulnerabilities are not included in the scan summary.)

FIXED

Sarif reports

Fixed problem with generating sarif reports.

FIXED

Debug logs

Fixed issue that debug logs were showing URLs that contained sensitive data.

IDE Plugins

In March we released the following IDE plugin version:

  • VS Code Extension - 2.0.14 (uses CLI v2.0.42)

Improvements and Bug Fixes

Added the SCA Realtime scanner tool, which enables all VS Code users to run an SCA scan on the project in their workspace and view results in the VS Code console.

Tip

This is a free tool that doesn't require a Checkmarx One or Checkmarx SCA account. For Checkmarx users, the results are not synced with their account.