Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
ThreadFix Version Release Notes
For REST API updates, refer to the Change Log
3.1.2
May 2022
Note |
---|
To upgrade to 3.1.2 please see the Upgrade & Migration guides. Users interested in migrating from 2.8.6 to 3.1.2 must follow the the 2.X to 3.X Migration process. Note: Migration from 2.8.5.1 to 3.1.2 is currently not supported. |
Helm
Key Update
Security update addressing user access to root information per an XML External Entity vulnerability identified during internal penetration testing. ThreadFix recommends updating to 3.1.2 to mitigate exposure.
Version Feature Changes
New versions of ThreadFix may deprecate, remove, and/or reintroduce features. To view a list of feature changes please see below:
No new feature changes in 3.1.2
To view a complete list including prior releases, please view the 3.X Version Feature Changes list.
Legacy 3.X Release Notes
.
X Release Notes3.1.1
April 2022
Warning |
---|
The National Vulnerability Database has identified a high risk exploit, Spring4Shell, which affects applications running Tomcat as a WAR deployment. For more information refer to CVE-2022-22965. In response Coalfire has tested ThreadFix to assess risk and mitigation options and recommends users update to ThreadFix version 3.1.1 to mitigate risk of exposure and provide security enhancements. |
Note |
---|
Migration from 2.8.5.1 to 3.1.1 is currently not supported. Users interested in migrating to 3.1.1 must upgrade to 2.8.6 first then continue with the 2.X to 3.X Migration process. |
Key Updates
The Black Duck Remote Provider Integration has been enhanced allowing multiple users to select the option to import applications by Application or Application Version
Contrast Remote Provider enhancements
Enhancement when importing vulnerabilities to include Contrast Finding comments
Addition of support for OSS Dependency Findings imports to Contrast scans
Additional Contrast Statuses have been provided for mapping by ThreadFix
Addition of Scan Orchestration option to Acunetix 360 Remote Provider
Fortify SCC enhancements
Now allows importing Sonatype SCA vulnerability data
Support added for flexible tag definitions
The AppScan on Cloud integration has been updated to allow importing applications that have scans but do not have vulnerabilities
Added support for GitHub Dependabot (Beta) Remote Provider
New/Updated API
New versionName and versionNativeId API calls for Black Duck Remote Provider, allowing users to import scans from multiple versions of a project at once
New Fetch Applications and Get Scans API calls for Contrast Remote Provider
The Get Application by Name and Get Application in a Team by Unique ID calls have been merged into Get Application by Name or Unique ID
The Create Application and Update Application REST calls have been updated to include additional fields
General Improvements
Remote providers can now also be instantly managed via drop-down menu from the Remote Provider list page
Image ModifiedCVSS scores now available as part of Finding Details
Image ModifiedGeneral UI improvements
General bug fixes and improvements
Feature Changes
Note the following changes to features with the introduction of ThreadFix 3.1.1:
Reintroduced
The Check Remote Provider Application Import Status endpoint has been reintroduced
Coverity Remote Provider has been reintroduced
Deprecated and Removed
For other REST API updates, refer to the Change Log
The Black Duck call "/remediating" has been deprecated by Black Duck in version 2021.10.0 and has been replaced by "/upgrade"
The SSVL Converter Tool deprecated in 3.1 has been removed
Legacy 3.X Release Notes
Expand | ||||
---|---|---|---|---|
| ||||
3.1October 2021
Key Updates
New/Updated API
General Improvements
Feature ChangesNote the following changes to features with the introduction of ThreadFix 3.1: Deprecated and Removed
Limitations, Scheduled for Enhancement Post 3.1
Absent, Scheduled for Re-introduction Post 3.1
3.0.8March 2021
Security Updates
Key Updates
General Improvements
Installation and Upgrade Guides:3.0.7October 2020 General Improvements
3.0.7 also contains the following AppSec updates. Key Updates
General Improvements
|
Table of Contents
Table of Contents |
---|