Added
- Wiz syncs can skip vulnerability and end-of-life findings on container images that exist only in a registry and that no workload runs, by setting wizDropUndeployedRegistryImages to true
- Wiz vulnerabilities now show, in their plugin output, how many Wiz issues each finding contributes to by severity and whether a container image was scanned from its registry or a running workload
- eMASS system export import now accepts the eMASS export .zip directly, including its artifact files
- Plan-field routing can match a plan field that lists several identifiers, such as every ComponentID of a system, with --plan-match-multi-value, and can treat named prefixes such as COMP- as not part of an identifier with --ignore-id-prefix; aws sync_findings_by_plan_field supports both
- Axonius v2 can route assets and findings to security plans by a plan field that lists several identifiers, such as a system's Component IDs, with the new sync_assets_by_plan_field and sync_findings_by_plan_field commands, which sync an identifier that two plans list to both and close records that left a plan unless --suppress-mop-up is given
- Scanner integrations can now pass KEV, internet reachability and EPSS data through to vulnerabilities for FedRAMP VDR evaluation
- Evidence, Change and AppGroup models include the new platform fields externalKey, canApproveChanges and canRequestChangeApproval
Changed
- eMASS system export import now exits with an error status when the import records any error, so scheduled runs no longer report a failed import as successful
- eMASS CAC authentication now uses the OpenSSL 3 PKCS#11 provider instead of the deprecated OpenSSL engine interface, and works through a tunnelling proxy
- Asset syncs run their per-asset follow-up lookups in parallel for faster imports
- Faster vulnerability imports by leaving vulnerability-to-asset links to the platform instead of creating them a second time from the CLI
- Security Hub compliance runs routed by plan field now report how many finding resources were left out of every plan's control assessments
Fixed
- Re-importing an eMASS system export no longer duplicates control tests and test results
- eMASS system export import now assigns new controls to the Security Plan's System Owner or ISSO and new assessments to the matched eMASS tester, ISSO, or System Owner instead of the importing user
- eMASS system export import no longer reads artifact files from outside the export folder
- Imports that run past midnight no longer risk closing findings that the same import had just created
- Importing the same eMASS system into more than one Security Plan no longer moves POA&Ms from one plan to another
- eMASS system export import now sets POA&M statuses the tenant actually offers, no longer blanks a POA&M's Identification on re-import, and keeps the system acronym on tenants without a DoD package
- eMASS system export import now imports POA&Ms on DoW tenants, with their due dates, owners, status and severity, and records control narratives, statuses and Not Applicable results correctly
- JCAM information types now match RegScale information types whose titles carry SP 800-60 section numbers or spell "and" as "&", re-importing no longer detaches information types from their plan, and a plan whose information types match none is reported as failed
