CLI 6.46.0

Added

  • jcam check_config now names any role declared in jcamSystemRoles that matches no point-of-contact position in any JCAM system in scope, so a role that will be created and stay empty is visible before anyone builds it.
  • Ability to create and manage RegScale service accounts from the CLI and the interactive TUI, with a warning before an existing service account token is replaced by a user login
  • An agency-defined item can declare what its JCAM values mean in RegScale, so a field whose two systems word the same answer differently now imports
  • A JCAM field mapping can name a JCAM key the shipped profile does not read, so a tenant can import one more field without waiting for a release

Changed

  • Several JCAM values addressed to one custom field are now combined instead of the last one silently replacing the rest
  • A JCAM collection spread across several fields now reports values with no field to land in, and clears fields a shorter run no longer fills
  • All of a system SORN notices are imported across the available slots, instead of only the most recent one
  • A JCAM destination matching a form heading is reported by check_config instead of failing once per record during an import
  • JCAM answers Financial or Non-Financial for a system, and the recommended mapping now translates it so a checkbox destination accepts it
  • Custom field save failures now name the record and the fields that were sent
  • JCAM report names are configurable, so an instance whose reports are named differently no longer needs a code change
  • JCAM request timeouts are configurable, and report endpoints get a longer budget than the rest so a large report has time to build
  • The JCAM connection test now probes the control parameters endpoint, so a credential that cannot run import_parameters is reported before the import instead of during it
  • A JCAM control status this importer cannot read now leaves the existing status alone instead of recording the control as Not Implemented
  • The CLI now says when it creates an init.yaml in the current directory, instead of silently running against template defaults
  • JCAM imports resolve the mapping profile and the plans in scope through one shared entry point, so a plan with no JCAM system id is reported the same way by every import instead of three different ways.
  • The JCAM dry run separates values a field would refuse from values written without fitting the field, and exits non-zero for either
  • The JCAM dry run shows the value a field would actually store, so a checkbox plan reads "true" rather than "Yes"
  • The JCAM dry run reports values a destination field would refuse, instead of listing them as writes it would perform
  • The JCAM assessment import says why a control produced no assessment, naming any result values it does not recognise
  • JCAM values addressed to a field that holds one value are no longer joined into it, and check_config reports a mapping that would do so
  • A JCAM collection now writes every slot it declares on every run, so a slot with no value is emptied rather than keeping an answer the source has stopped giving

Fixed

  • SARIF sync now links findings to the asset given on the command line no matter which identifier field that asset uses
  • A scan whose findings match no asset now stops with an explanation instead of finishing quietly having imported nothing
  • SARIF compliance sync against a component now finishes in seconds rather than minutes
  • Controls that a SARIF scan checked and found clean are now marked as planned instead of being left untouched
  • SARIF findings for generic injection, forced browsing, incorrect privilege assignment, and active debug code now map to ASVS controls
  • Control implementation status updates that fail are now reported in the run summary instead of being silently discarded
  • Control implementations set to a planned status by a compliance scan now save successfully instead of being rejected for missing required fields
  • A JCAM field mapping override now moves the fallback that shared its destination, so one value needs only one custom field
  • Agency-defined JCAM values are now written through the same mapping layer as everything else, so they find their field wherever it sits on the module and are shaped to what that field accepts, instead of being refused for sitting on the wrong tab or stopping the import with an unexplained server error.
  • JCAM control import no longer refuses a tenant over an acronym custom field the recommended field layout does not use
  • An inherited JCAM control no longer fails to import on a plan whose Control Origin list spells it "Inherited from Provider"
  • A JCAM value mapping now applies to the pre-rename key as well, so a tenant vocabulary is not ignored on deployments that send it