A broad feature release expands scanning, policy, reporting, remediation, notifications, telemetry, integrations, and output capabilities. It also includes security hardening and stricter scan constraints, alongside many correctness and runtime fixes.
Action needed (2)
securityGo dependency security vulnerabilities
Dependabot fixes security vulnerabilities in Go dependencies shipped with the release.
security
gosecSAST findingsThe release remediates
gosecSAST findings in the Go codebase.
Check if affected (10)
securityGrafeas filtering through
resourceURLApplies if you run imagescan.
breakingClient-supplied
accountandaccessKeyin scan requestsApplies if you use scan requests.
breakingHard validation for
--include-controlsApplies if you configure
--include-controls.- + 7 more on the release page
Plan ahead (1)
deprecatedThe
--fail-thresholdflag, hidden and deprecatedApplies if you configure
--fail-threshold.