CLI 6.49.0
September 28th, 2026
[6.49.0] - 2026-09-28
Added
- Wiz STIG and CIS benchmark results now record, in each control test's observations, which configuration criteria produced the pass or fail result and what Wiz found on the host
- Wiz Ports and Protocols records now include ports reachable over VPN, from another cloud account or from a custom IP range, flag VPN-reachable ports, and record Wiz's exposure level in the purpose
- Optional Wiz setting that keeps only the stable Representative Resource when a workload is also reported as an ephemeral instance, so the asset register stops double-counting it, with a dry-run mode that reports what would collapse without changing anything
- Improved schema-drift detection tooling reliability
- Warning in CLI logs when the connected RegScale platform returns fields the CLI does not recognize, signaling the CLI may be behind the platform version
- Catalog revision family, number, and state are now available on catalog records
- The CLI's ControlImplementation model now carries inheritanceModel, so a caller can read
back whether a control is offered for inheritance and as what. Writing it still goes
through the platform's provider-model endpoint, which sets it and the legacy inheritable
flag together. - Complete example configuration file covering all supported settings
-
- Options to save a new service account token to init.yaml or copy it to the clipboard
- Wiz excessive access findings are now synced, covering identity over-permissioning alongside the other Wiz finding types
- Axonius sync_assets can now sync every asset in a file to a single specified security plan instead of mapping by FISMA ID
- New
regscale trust-center vdr pushsends a Security Plan's RegScale issues to the Trust Center VDR bulk-ingest feed (idempotent per issue, batched, exits non-zero on rejects), andvdr job-templateprints ready-to-paste systemd unit/timer and cron schedules for a turnkey push job
Changed
- JCAM imports no longer report a 500 as a failure. JCAM answers 500 both when an endpoint
has no data and when something is wrong, and nothing in the response tells the two apart,
so these are now counted and reported separately as indeterminate. A domain where every
call answered 500 and nothing succeeded is still called out as an outage. - Platform secret store resolution is now opt-in via the secretStoreEnabled setting or SECRET_STORE_ENABLED environment variable, and any problem pulling secrets while enabled produces one clear, actionable message naming the cause and the fallback. Upgrading from 6.47.0, where resolution was always on: if you removed credentials from init.yaml after running push-secrets, set secretStoreEnabled to true to restore resolution
- JCAM control inheritance import now records inheritance linkage to support accurate display in RegScale
- The first Wiz sync after upgrading imports previously excluded resolved and ignored cloud configuration findings, which on an established tenant can be substantially more records than the open findings alone
- The provider inheritance-model setter is now InheritanceProviderModel.set_for_controls, and rejects an unrecognized inheritance model before sending it to RegScale
Fixed
- Wiz messaging services such as SNS topics and SQS queues now sync as Applications instead of Other, and an unmapped Wiz asset type is reported instead of being silently classified as Other
- An invalid Wiz filter setting now stops the sync with a message naming the setting, instead of failing with a raw JSON error or silently pulling the entire tenant unfiltered
- JCAM artifact import no longer re-downloads and re-uploads the same files on every run.
The check for "already imported" was built by a different rule than the filename RegScale
stores, so any artifact whose name contained punctuation never matched and was attached
again each time. - A GraphQL field-level error, such as one field a service account may not read, no longer aborts the whole sync; the remaining fields are imported and the refused fields are named in the log
- FedRAMP POA&M import no longer sets an asset's type from the free-text "Resources Required" column
- Wiz issue and STIG syncs now read the configured Wiz settings block instead of falling back to built-in defaults, so scheduled completion dates, past-due handling and known-exploited-vulnerability windows all follow the Wiz configuration, with high severity shifting from 60 to 90 days under the shipped defaults on plans that do not define compliance-setting SLAs
- Asset, issue, and vulnerability updates no longer drop platform fields the CLI did not previously recognize
- ServiceNow date parsing now zero-pads very small years consistently across platforms, preventing invalid dates on Linux
- AWS Security Hub checklist statuses now reflect compliance pass and fail results instead of always showing Not Reviewed
- Wiz vulnerability sync now reports when a Representative Resource arrives in an unrecognized provider format, instead of silently skipping the findings it would have rolled up onto the parent asset
- JCAM inheritance now appears in RegScale. The importer marks a provider's control as
inheritable using the inheritance data JCAM already sends, rather than inferring which
plans are providers from their system type. Nothing was being marked before, so the new
inheritance API refused every link and the older display had no inheritable source controls
to show. - eMASS CAC authentication settings in the example configuration no longer conflict with baseline sync settings
- Wiz cloud configuration findings are now synced in every status, and a misconfiguration ignored in Wiz as a false positive, by-design setting, accepted risk or exception carries that adjudication into the RegScale issue's deviation fields
- Wiz findings resolved at the source are now closed in RegScale again, after a query that failed on every run stopped suppressing stale-finding cleanup for the whole sync
- The JCAM POA&M import summary now counts POA&Ms. Its successes were security plans and its
failures were individual records, so the numbers could not be reconciled against anything
without reading the source. Plan-level outcomes are reported as notes beneath the tally,
and a plan whose POA&Ms could not be fetched, a failed POC lookup and a refused custom
field value each have their own domain. - Qualys VMDR report import now creates issues successfully instead of failing, and their due dates honor the configured remediation timelines for each severity
- Axonius pull_data_axonius no longer reports a successful import when it has only downloaded a file, and names each output file after the saved query so pulling several in sequence no longer overwrites them
- A failed Wiz authentication now only retries alternative token endpoints within the same Wiz deployment, so credentials for Wiz for Gov are never sent to a commercial endpoint or the reverse
- jcam
import_sspnow creates each security plan with the JCAM system id in the field the loaded mapping profile nominates, rather than always inotherIdentifier. On the recommended profile that field is the System Acronym and the id belongs ontrackingId, so a plan whose front matter pass then failed was left with notrackingId-- invisible to the next run's plan lookup, and created a second time. - Missing pytz dependency that caused commands to fail on a fresh install
- Axonius README now documents the sync_assets --schema option and its two field mappings
- QRadar event sync no longer duplicates findings on every run, compliance assessment now credits the event categories and log sources QRadar actually reports, and query_events no longer crashes when a plan lacks one of the mapped controls, rejects query values that could alter the search, labels POA&Ms and evidence with the field and time window that were queried, and exits with an error when a query-mode run fails
- Slow scanner imports caused by repeated asset and issue lookups, and issues that failed to link to assets created during the same run
- Vulnerability imports no longer slow to a crawl when the tenant lookup fails
- Axonius v2 asset sync no longer fails with a bad request error
-
- The CLI no longer clears the root logger's handlers when used as a library, so host applications and test harnesses keep receiving log records
-
- Qualys VMDR report re-imports now close stale vulnerabilities that no longer appear in the latest report
- eMASS workbook imports no longer erase stored data when a tenant disables a form field. A disabled column is now left at whatever the server already holds rather than being written back empty, across the hardware and software inventory, POA&M, SLCM, security categorization, control test results and eMASS baseline imports. An import that fails because the security plan is not visible, or because the workbook does not match the target plan, reports one error line instead of a Python stack trace, and a column the server refuses is now counted as an error rather than reported as a clean run. The software In Service Data column reaches its field instead of a retired one, the hardware inventory reports IP address values it discards rather than dropping them silently, a dry run no longer contacts the instance, and the Test Result import prefers a real data sheet over a boilerplate Template tab.
- Defender sync_cloud_resources now creates virtual network assets whose Azure address space is a list of prefixes, instead of failing with an asset validation error
- Connector syncs, including GCP, Wiz and Jira, now stop with an error naming the missing security plan or component when pointed at one that does not exist, instead of writing records that no plan can reach
