CLI 6.42.32
August 28th, 2026
[6.42.32] - 2026-08-27
Added
- FedRAMP SSP interconnect and cryptographic module import commands, and an optional SSP ID on FedRAMP docx import so an existing plan is updated instead of duplicated
Fixed
- Bulk scan import no longer crashes when routing Prisma Cloud files
- OCSF and SBOM import command groups are now reachable from the CLI
- GCP sync asset-type, label, severity, source, and evidence options now change sync behavior instead of being silently ignored
- SAP Concur SysDig imports now honor the supplied scan date and the SysDig and Tenable subcommands are always registered
- Multi-collection GraphQL queries such as reminder lookups now paginate each collection independently instead of silently skipping records past the first page
- Cleanup bulk-delete commands now remove every matching record instead of silently stopping after the first page
- CVE cleanup discovery now finds issues with multiple CVEs instead of silently returning nothing
- eMASS control export retrieves every control with assessments for plans with more than 50 controls
- eMASS SLCM import no longer deletes control implementations missing from the workbook unless explicitly requested, and semi-annual review frequencies now calculate as 182 days
- eMASS POA&M pushes now carry issue details such as severity, comments, and completion dates instead of silently empty fields, and file-based DoD PKI client certificates can be configured
- Connector syncs from different vendors into the same security plan no longer close each other's findings
- Tanium Cloud compliance sync now passes through control mappings when available and alerts loudly instead of silently dropping every finding
- Dependabot sync now retrieves every alert page, fetches GitHub data once per run, and no longer creates duplicate issues on repeat runs
- GitLab issue sync now retrieves every page of issues and tracks them under a GitLab-specific identifier
- OpenSCAP compliance sync now ships its CCE mapping file and fails loudly when a configured mapping override is missing instead of silently resolving no controls
- STIG mapper now evaluates each asset against its own existing mappings so assets after the first receive complete STIG mappings
- File-based scan imports quarantine unparseable records with clear warnings instead of creating placeholder assets and findings
- Active Directory sync now aborts safely when the mapped role is missing instead of proceeding into the role-removal and deactivation flow
- Intune device sync compares versions numerically and correctly classifies macOS devices
- FedRAMP Rev 5 POAM export is now read-only by default with an opt-in flag for comment write-back, and comment templates and POAM ID prefixes are configurable
- Removed unreachable FedRAMP compatibility aliases and duplicate DRF import command that could never be invoked
- Veracode imports now assign correct severities instead of collapsing every finding to Low
- Wiz rollup and asset-identifier behaviors are now protected by contract tests to prevent silent regressions
- Model editor no longer carries one model's field layout into the next when processing multiple models in a single run
- Login failures now exit with a clear error message instead of crashing with an internal variable error
- Okta bearer tokens are no longer written to log output during authentication
- STIG checklist file parsing is hardened against XML external entity attacks
- Microsoft Defender API error handling no longer relies on assertions that disappear in optimized builds
- Salesforce sync no longer carries results across repeated runs and handles missing API responses without crashing
- Burp scan imports now accept export timestamps with or without a timezone
