[6.50.0] - 2026-10-06
Added
- Wiz asset syncs now fill the public-facing FQDN, IP address and URL fields from the application endpoints Wiz confirmed, and network exposure vulnerabilities now carry their port and protocol
- AWS Audit Manager sync now filters assessments with
--tagsand scopes evidence to tagged resources with--resource_tags - AWS Security Hub compliance sync commands assess controls from Security Hub standards, route results to one or many security plans by plan field or ComponentID mapping file, and record the unmodified Security Hub findings as evidence by default
- CLI options now accept both snake_case and kebab-case spellings everywhere, with kebab-case shown in --help, and unambiguous Security Plan ID options accept a friendly --ssp-id alias
- Opt-in
REGSCALE_STRICT_EXIT_CODES=1makes scanner syncs that finish with item-level failures exit 3 instead of 0, and the CLI exit-code contract is now documented - Optional machine-readable output via
regscale --output json(orREGSCALE_OUTPUT=json), including a standard run summary and JSON records for supporting commands - New
--previewflag on cleanup deletes, JCAM and eMASS push commands andset_permissions loadlists every record that would be created, updated or deleted without writing anything - New configurations store integration secrets in the RegScale secret store by default, and existing configurations can move theirs with the reversible regscale config migrate-secrets command
- Automated secret scanning on every source change to keep credentials out of published releases
regscale config validatechecks init.yaml for unknown, deprecated, missing and mistyped keys and leftover placeholders, with JSON output and a non-zero exit on errors- Read-only config mode (
REGSCALE_CONFIG_READONLY=1or--no-write-config) never creates or writes init.yaml, and every setting can also be supplied as aREGSCALE_<NAME>environment variable - Set REGSCALE_USE_PROXY_ENV=1 to route RegScale API and integration traffic through HTTPS_PROXY, HTTP_PROXY and NO_PROXY, and custom CA bundles now apply to proxied and GraphQL connections
- Trust Center, QRadar and Prisma Cloud CSPM requests now retry automatically with bounded backoff when the vendor API throttles or is briefly unavailable
- Releases now include signed build provenance for the wheel and sdist, keyless cosign signatures and SBOM attestations on the Docker images, and a CycloneDX SBOM attached to each GitHub release, with verification steps in the release verification guide
- Deprecated commands, options and settings now print a warning naming their replacement and the release they will be removed in, following a published deprecation policy
- Shell tab completion for bash, zsh, fish and PowerShell (
regscale completion), aregscale integrations listcommand showing each integration's category, description and docs link, and aregscale --helpgrouped by category - Usage examples in the
--helpof the most-used commands, and corrected command examples in the documentation and in several AWS command help pages - Opt-in structured JSON logging via
regscale --log-format jsonorREGSCALE_LOG_FORMAT=json, with a run ID shared with the run summary and secret values redacted from every log line - Added a --force-refresh option to Axonius v2 sync commands to re-pull every record instead of only recently changed ones
make helpnow lists the model schema and Azure AD sync regeneration commandsregscale devsecops runvalidates the full.regscale-devsecops.ymlconfiguration (change, approval, targets, mapping, SAR, policy, assess, schedule and module settings) and reports each problem with its field path, line number and accepted valuesregscale devsecops ssp snapshotcommand that exports a Security Plan's control IDs, catalogs and evidence-type mapping coverage to a credential-free file for offline control resolution- Pipeline readiness check with
regscale devsecops doctor, reporting TLS, service-account identity and expiry, missing or excess permissions, configured SSP and component, mapping coverage and schedules - Pipeline Change records with typed trace links to work items, pull requests, approvals, builds and artifacts via
regscale devsecops change open|update|close regscale devsecops evidence collectandpublishcommands that capture branch protection, pull request approvals, CODEOWNERS and JUnit test results as evidence mapped to the security plan and its controlsregscale devsecops sbom generate,diffandpublishcommands that produce SBOMs from the GitHub dependency graph or syft, compare them with the previous release and publish them as inventory, evidence and change trace linksregscale devsecops scan importcommand that imports SARIF, Trivy, Grype and Wiz CLI results as vulnerabilities and records them as control assurance on the target Security Plan, whatever framework it usesregscale devsecops openssf scanandsyncpublish results to Security Plans without OSPS Baseline controls as a summary assessment and evidence record mapped to the plan's own controls, record them in the run ledger, and weigh AI-assessed observations as added risk onlyregscale devsecops schedule showandapplyset the OpenSSF drift-monitor cadence as a RegScale Orchestration Hub job or a scheduled GitHub Actions or GitLab workflow, choosing between the Scorecard API and a fresh scan for each repositoryregscale devsecops assesscommand that rolls a pipeline run's evidence up to findings for the Security Plan's own controls, publishes them as assurance results, raises issues for failing tool-observed results and closes them once they pass, without changing implementation status unless askedregscale devsecops sar buildandsar validatecommands that produce the run's OSCAL Security Assessment Results and assessment plan from the run ledger and validate them against the pinned NIST OSCAL schema, failing closed when no schema is availableregscale devsecops sar mergebuilds a release SAR from the run SARs between two release tags, andsar publishattaches a run or release SAR as a CI artifact, SSP file, SSP child assessment or Evidence recordregscale devsecops attestwrites an in-toto attestation over the run ledger, SAR and policy decision, optionally Sigstore-signs it (never in FIPS mode), attaches it as Evidence and has the platform verify itregscale devsecops gate,policy evaluateandpolicy pullcommands that evaluate the digest-locked OPA gate bundle against the run's policy input without RegScale credentials, map the decision to a CI exit code, and skip credentialed steps on fork pull requestsregscale devsecops policy initcommand that locks a framework-neutral default gate policy, deciding on evidence types, change categories and per-check OpenSSF Scorecard thresholds, without a RegScale connectionregscale devsecops change request-approvalandchange verifycommands that submit a Change to the platform's tolerance-policy approval and gate deployments on approved artifact digests, withchange closealways recording the deploymentregscale devsecops change shadow-reportcommand that compares shadow-mode Change approval decisions with CCB outcomes, reports agreement, false auto-approval rate, auto-approval share and approval wait time, and checks each component against configurable readiness thresholds before enforcement- Opt-in
regscale devsecops review impactcommand that reviews a change against the SSP's own controls with a pluggable AI provider (Anthropic, Amazon Bedrock, Azure OpenAI or RegML via theaiextra), records an advisory AI-assessed result and writes the Change's impact analysis section regscale devsecops scan import --offlinerecords a scan in the run ledger without RegScale credentialsregscale devsecops run --stage pr|build|release|deploy|scheduledruns the modules the manifest enables for each pipeline stage, split into a credential-free collect job that writes a verifiable run bundle and a trusted publish job that publishes it- OpenSSF OSPS Baseline assurance commands (
regscale devsecops openssf syncandscan) that run or ingest Scorecard, OSV-Scanner, Privateer, Security Insights, OpenVEX and SLSA provenance results and report per-requirement test results, control assessments, issues and evidence against an OSPS Security Plan - Signed OSPS conformance attestations (
regscale devsecops openssf attestandverify) packaging verdicts as in-toto statements with optional Sigstore keyless signing via theregscale-cli[attest]extra - Scheduled OSPS drift detection (
regscale devsecops openssf monitor) that compares published Scorecard results with the Security Plan and flags regressed controls without running scans - Evidence tier (Declared, Observed or Verified) recorded on OSPS assessments and control test results
- Reusable GitHub Action that runs OSPS Baseline assurance, with an optional signed attestation, in a pipeline
- Self-contained HTML OSPS conformance report that pipeline runs can publish as an artifact
- QRadar compliance assessment minimum event threshold is now configurable through min_events in the qradar config block
regscale devsecops change open|updateoptions for the Change's title, description, case notes, test results, outage summary, type, priority, owner, change window and test date,--change-idwith--adoptfor existing records, achange attachcommand for files and URL links,--output jsonon the change, evidence and SBOM publish commands, andsbom publish --parent-asset --name
Changed
- AWS Security Hub tag filtering is now applied server-side so fewer findings are pulled over the wire
- Command reference documentation now covers every CLI command, with a complete generated command index and corrected command, option, and configuration examples across the user guides
- Dependency versions are now capped below their next major release so a new major version of a third-party package can no longer break a fresh pip install
- eMASS client reads and writes the eMASS API v3.31 field names for systems, POA&Ms, milestones and hardware, still reads the older names from earlier eMASS versions, and now sends the required POA&M source field under its correct name
- QRadar assess-compliance now runs through the standard compliance sync, creating a QRadar SIEM asset and scan history, and attaches the recommended fix to issues for failed controls
- Scanner asset syncs no longer look up or store raw source data per asset, which makes large asset imports faster
- FedRAMP SSP XML import no longer calls the retired OSCAL validation service or attaches an OSCAL validation report
Fixed
- License-gated commands now honour the platform's 5-day grace period after the RegScale license expires, warning on each command with the expiry date and grace days left, and after it ends report that the license expired on that date
- jcam import_ssp no longer stops partway through creating plans when JCAM reports a system with no categorization or system type, a new plan now gets its organization at creation, and one organization that cannot be read no longer stops the import
- JCAM control inheritance import again writes the plan lineage and inherited control records the RegScale inheritance views read
- FedRAMP CIS/CRM import now sets the inheritance model on control objectives and rolls it up to the control implementation
- Control matching now skips a missing, blank or non-text control ID instead of crashing the import
- Help text for the Axonius combine_data_parts and file_stats commands, and corrected descriptions for pull_data and pull_data_axonius
- Negated CLI flags (--no-x) now accept both snake_case and kebab-case spellings
- Settings supplied through environment variables are no longer written into init.yaml, so a secret in the environment can no longer overwrite a secret-store reference on disk
- A secret passed to
regscale config --paramis no longer written to the debug log - Prisma Cloud imports no longer drop vulnerabilities whose published or fix dates are millisecond timestamps
- Issues whose asset identifier list is too long for the field now say how many identifiers were left out
- Scanner imports no longer silently drop every vulnerability when the RegScale tenant lookup fails
- GitHub SBOM sync no longer fails when the security plan already has component mappings, and the client-side outdated-issue closure and control objective lookup by catalogue no longer fail on every call
- JCAM import no longer stops when a FISMA rollup would move a security plan under a different parent; that plan is skipped and reported in the run summary
- Axonius v2 sync no longer fails on Axonius 6.1, and synced assets and findings now include hostname, IP, OS, CVE, severity and other details
- Fixed debug log issue in login and api modules.
- JCAM inheritance import no longer resets provider controls to not inheritable, and skips inheritances that name a plan as its own provider
- Updating an existing Security Plan no longer fails when the instance has disabled plan fields; those fields are skipped with a warning
- Asset imports, including Nessus, no longer fall back to slow one-by-one uploads when the same host appears more than once in a file
- QRadar compliance assessments now state why each control passed or failed and recommend how to fix it, instead of only the result
- Trivy and Grype imports now link vulnerabilities to their scanned assets
- DevSecOps hints, example manifests and the regscale-devsecops GitHub Action now match the commands and configuration keys the CLI actually reads, and unread module keys log a warning
- An invalid RegScale token no longer appears in login error messages, and
devsecops runcollect jobs no longer create an init.yaml in the working directory or refuse to publish a bundle whose configuration file differs only in line endings - QRadar assess-compliance now creates issues for failed controls when complianceCreation is set to Issue or POAM
- Wiz inventory sync no longer fails when no project ID is supplied, and several integrations no longer fail on null values returned for optional fields
- Microsoft Defender for Cloud resource sync no longer fails on subscriptions with more than about 96,000 resources
- Microsoft Defender syncs now follow relative pagination links from the Defender API instead of sending them to the RegScale server
- Records queued for batch saving, such as Splunk Data records and Jira or SonarCloud issue updates, are no longer dropped when disableCache is enabled
- GCP runs now warn when a configured service account credential is invalid, name the rejected setting and the reason, and stop with an error when no configured credential is valid instead of continuing on a different credential
- regscale evidence start now creates the assessment for each project listed in list.json, instead of stopping with an error or attaching one program's results to another project
- Platform version checks now treat an internal build of the RegScale platform (one that reports a build number and date instead of a release version) as a development build rather than as a very new release. Features that stay off on development builds, such as linking one issue to multiple controls, are no longer switched on against these servers, and a server that reports an unrecognized version no longer causes a version-parsing error.
- Updating an existing task under a parent record that already has tasks no longer fails
- Installing the CLI now requires a PyJWT release free of the known critical and high severity vulnerabilities
