CLI 6.42.32

[6.42.32] - 2026-08-27

Added

  • FedRAMP SSP interconnect and cryptographic module import commands, and an optional SSP ID on FedRAMP docx import so an existing plan is updated instead of duplicated

Fixed

  • Bulk scan import no longer crashes when routing Prisma Cloud files
  • OCSF and SBOM import command groups are now reachable from the CLI
  • GCP sync asset-type, label, severity, source, and evidence options now change sync behavior instead of being silently ignored
  • SAP Concur SysDig imports now honor the supplied scan date and the SysDig and Tenable subcommands are always registered
  • Multi-collection GraphQL queries such as reminder lookups now paginate each collection independently instead of silently skipping records past the first page
  • Cleanup bulk-delete commands now remove every matching record instead of silently stopping after the first page
  • CVE cleanup discovery now finds issues with multiple CVEs instead of silently returning nothing
  • eMASS control export retrieves every control with assessments for plans with more than 50 controls
  • eMASS SLCM import no longer deletes control implementations missing from the workbook unless explicitly requested, and semi-annual review frequencies now calculate as 182 days
  • eMASS POA&M pushes now carry issue details such as severity, comments, and completion dates instead of silently empty fields, and file-based DoD PKI client certificates can be configured
  • Connector syncs from different vendors into the same security plan no longer close each other's findings
  • Tanium Cloud compliance sync now passes through control mappings when available and alerts loudly instead of silently dropping every finding
  • Dependabot sync now retrieves every alert page, fetches GitHub data once per run, and no longer creates duplicate issues on repeat runs
  • GitLab issue sync now retrieves every page of issues and tracks them under a GitLab-specific identifier
  • OpenSCAP compliance sync now ships its CCE mapping file and fails loudly when a configured mapping override is missing instead of silently resolving no controls
  • STIG mapper now evaluates each asset against its own existing mappings so assets after the first receive complete STIG mappings
  • File-based scan imports quarantine unparseable records with clear warnings instead of creating placeholder assets and findings
  • Active Directory sync now aborts safely when the mapped role is missing instead of proceeding into the role-removal and deactivation flow
  • Intune device sync compares versions numerically and correctly classifies macOS devices
  • FedRAMP Rev 5 POAM export is now read-only by default with an opt-in flag for comment write-back, and comment templates and POAM ID prefixes are configurable
  • Removed unreachable FedRAMP compatibility aliases and duplicate DRF import command that could never be invoked
  • Veracode imports now assign correct severities instead of collapsing every finding to Low
  • Wiz rollup and asset-identifier behaviors are now protected by contract tests to prevent silent regressions
  • Model editor no longer carries one model's field layout into the next when processing multiple models in a single run
  • Login failures now exit with a clear error message instead of crashing with an internal variable error
  • Okta bearer tokens are no longer written to log output during authentication
  • STIG checklist file parsing is hardened against XML external entity attacks
  • Microsoft Defender API error handling no longer relies on assertions that disappear in optimized builds
  • Salesforce sync no longer carries results across repeated runs and handles missing API responses without crashing
  • Burp scan imports now accept export timestamps with or without a timezone