CLI 6.48.0

[6.48.0] - 2026-09-21

Added

  • JCAM import commands accept a repeatable plan id so a run can be narrowed without editing the configured filter
  • Wiz issue sync now brings over issue notes, the affected resource's cloud console link, project business impact, policy type, and linked service tickets
  • Wiz issues are now synced in every status, and an issue rejected in Wiz as a false positive, accepted exception or won't-fix carries that adjudication into the RegScale issue's deviation fields
  • Splunk verify-forwarding command to check whether the RegScale platform can reach its configured log-forwarding destinations
  • JCAM imports can name the compliance setting new security plans are created on, instead of always using the platform default
  • GitHub and GitLab commands that route each repository to the security plan named by one of its topics
  • Microsoft Sentinel standalone alert sync for alerts that never became an incident
  • Azure Government support for the Microsoft Sentinel integration
  • Microsoft Sentinel workspace content sync for analytics rules, automation rules, data connectors, connector health, bookmarks, hunting queries, watchlists, and threat intelligence
  • Microsoft Sentinel KQL query command for reading a workspace's Log Analytics tables
  • Multi-workspace Microsoft Sentinel sync with per-workspace incremental checkpoints
  • Opt-in Microsoft Sentinel status write-back that closes incidents behind resolved RegScale issues
  • Microsoft Sentinel integration that syncs incidents and their affected hosts, IPs, and Azure resources into RegScale

Changed

  • Custom field values are written one request per record instead of one per value, with a refused record retried a value at a time
  • The first Wiz issue sync after upgrading will import previously excluded resolved and rejected issues as closed RegScale issues
  • Reduced install size and startup overhead by dropping the pandas dependency
  • Microsoft Sentinel entities now map to the record type that fits them, with accounts, mailboxes, cloud applications, and security groups inventoried as assets and files, hashes, URLs, and processes carried as finding evidence

Fixed

  • JCAM import reports when two milestones or interconnections share a name instead of silently keeping one
  • JCAM import no longer loses a POA&M or milestone when JCAM sends no date or a negative effort figure
  • JCAM assessment import now updates control implementation status and last-assessed date instead of failing on every control
  • Wiz issue synchronization no longer fails when a Wiz source rule returns no security subcategories
  • Custom field values are no longer lost when the platform refuses one value in the same save
  • Wiz network exposures now record their public or internal classification in a field the platform stores, instead of one it discarded
  • Wiz network exposures reported on both an ephemeral workload and its stable representative now produce a single ports and protocols record
  • Wiz vulnerability sync now completes for service accounts without permission to read Wiz comments, skipping only the comment data
  • JCAM artifact import downloads and uploads one file at a time, so a full disk no longer loses the whole run
  • JCAM assessment import now recognises Not Applicable results instead of silently dropping those controls
  • JCAM assessment import counts controls rather than security plans in its run summary, reports why controls produced no assessment, and recognises both spellings of the no-date value JCAM sends
  • Cloud assets with multiple network addresses now record a single IP address, so they match scanner findings correctly
  • File upload failures now report the server status code and message instead of a generic empty-response warning
  • Raw SBOM documents from GitLab and GitHub are now attached to the security plan when the platform refuses to store them on the SBOM record
  • SBOM records now store a consistent CycloneDX standard value regardless of how the source document spells it
  • Updated bundled dependencies to pick up upstream security fixes
  • JCAM control import records an inherited control as implemented, keeping the inheritance in the control origination field
  • GitLab and GitHub SBOM syncs now store the original SBOM document so package comparison and SBOM download work correctly
  • GitLab and GitHub SBOM records now appear on the repository asset instead of the security plan