CLI 6.38.0
August 6th, 2026
[6.38.0] - 2026-08-05
Added
- eMASS CAC authentication can trust a custom CA bundle (e.g. DoD PKI) for verifying the eMASS server certificate via emass.ssl_ca_cert or the EMASS_SSL_CA_CERT environment variable, with a matching --ca-cert option on emass_api register
Fixed
- Security patches for the bundled aiohttp and cryptography dependencies, resolving multiple high-severity advisories
- eMASS CAC registration now reads the server response reliably instead of erroring on TLS retry or an unexpected connection close, and reports the redirect target when the request is bounced to a gateway login (a sign the certificate is not a registered API client)
- eMASS CAC authentication now pins OpenSC to the PIV driver so dual CAC+PIV cards no longer intermittently fail with "PKCS11_get_private_key returned NULL"; override with OPENSC_DRIVER for legacy cards
- eMASS CAC registration now reports a clean error message instead of a raw stack trace when the server's certificate cannot be verified or when CAC transport setup fails (missing PKCS#11 engine or private-key load failure)
- SSP and Appendix A imports now bring in every sub-part of a control part, such as Part a(1) and a(2), instead of keeping only the last one
- SSP imports and updates no longer fail with a "field must be enabled to enter a value" error when a plan has a FedRAMP ID, which disables the Other and Private deployment model options in RegScale
- SSP saves no longer fail when any other form field is disabled in RegScale, and instead save without that field and report which fields were skipped
- FedRAMP SSP imports only record deployment model remarks when the deployment model is Other, instead of filling them in for public, private, hybrid, and government clouds
- AWS Inspector V2 POA&M exports now show AWS Inspector V2 as the weakness detector source instead of a generic Scanner Integration label
- AWS Inspector V2 syncs now close out issues and POA&M items for findings that are no longer reported by Inspector, including on repeat runs the same day, and skip the close-out when account, tag, or resource-type filters mean the run covers only part of the environment
- AWS Inspector V2 control mappings no longer report scanning coverage gaps against CM-6, which Inspector produces no configuration baseline evidence for; coverage gaps and container image scanning are now reported under RA-5, and SA-11 covers Lambda static code analysis only
