Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
ThreadFix Version Release Notes
For REST API updates, refer to the Change Log
Warning |
---|
October 2022 - Known Issue Warning: Following changes in the K8 APIs, installing or upgrading ThreadFix on Kubernetes versions 1.25 or newer will fail. This issue will be addressed in the next ThreadFix release. |
3.2
September 2022
Note |
---|
Users interested in migrating to 3.2 from 2.X must upgrade to 2.8.7 first then continue with the 2.X to 3.X Migration process. Users upgrading from 3.1.2 please view the expandable note below before upgrading. |
Expand | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
In ThreadFix 3.2, Minio requires the Minio secret data to contain the keys “rootUser” and “rootPassword” instead of “secretKey” and “accessKey”. When attempting an upgrade, some users may encounter the following error:
This error can be resolved by manually editing the Minio secret to change the data values to what is expected.
Change the following:
To:
Once complete, perform the upgrade procedure once again. |
Helm
Key Updates / Version Feature Changes
New versions of ThreadFix may deprecate, remove, and/or reintroduce features. To view a list of feature changes please see below:
Azure Dev Ops
Significant improvements to our integration with Azure Dev Ops including
Support for unique datatypes natively in ThreadFix UI
Performance improvements
UI indication of all required fields
Autocomplete and picklist support of applicable fields
2.X Feature Parity (3.X only)
Implemented the Sonatype remote provider utilizing the new 3.1 ingestion pipeline
Added Remote Provider application names to the Finding Detail page
Integration Enhancements
The following remote providers now ingest and store CVSS values: Acunetix 360, Black Duck, Netsparker, NowSecure, and WhiteHat Sentinel Source
Checkmarx can now ingest additional scanner detail and scanner recommendations for findings
Contrast date management enhancements to provide greater accuracy on finding discovery dates
Improved SonarQube severity mappings
The maximum number of Defect Profiles that can be associated with a single defect tracker has been increased to 1024
Improvement to Fortify SCC findings filtering
To view a complete list including prior releases, please view the 3.X Version Feature Changes list.
Addressed Reported Issues and Security Updates
Upgraded dependencies and images including Debian, Kafka, and ActiveMQ
Fixed intermittent import errors with Acunetix 360/Netsparker
WhiteHat API updates to support new requirements from WhiteHat
Improvement to UI messaging indicating when all remote providers have been mapped
Improvement to UI messaging indicating when an invalid scanId was used
The ThreadFix UI Help button has been adjusted to now direct to the Coalfire Support Portal
Issue | Resolution |
---|---|
Importing scan data from AsoC fails, displaying the following error message: “RestIOException: Invalid response from ASoC while fetching last scan date.” | Resolved ASoC integration errors on import |
A user without read-access could view all policy data for an application | The Policies tab in ThreadFix has been updated to address the information disclosure |
A vulnerability’s open and close dates will no longer shift with new scan uploads unless a reopen or close event occurs | Resolved scan delete error if it includes findings that belong to vulnerabilities that have been closed and reopened multiple times |
When trying to update Jira Defect Tracker integration credentials, a 403 error is received with the following message: “Failure. Message was : The defect tracker URL is not valid." | Resolved JIRA connection issue |
"You don't have permission for this team." error is received when attempting to move an application to another team using the Update Application API even with an Administrator Global role | The Update Application API has been updated to address the permissions error, allowing the application to be successfully moved |
User unable to save an LDAP-linked SAML configuration, receiving a “Display Name Config Not Found” error | This issue has been addressed in 3.2 |
Threadfix files incorrectly export with a filename of null instead of the associated application’s name | A fix has been provided to ensure the Threadfix files correctly export with associated application’s name |
Occasionally Qualys WAS Finding Scan Details and Scan Recommendation sections do not import | Version 3.2 corrects the reported issue with the scanner details and recommendations properly displaying |
Error importing Contrast cloud scans | Resolved imports failing for certain Ruby applications |
Legacy 3.X Release Notes
Expand | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||
3.1.2May 2022
Helm Key Update
Version Feature Changes New versions of ThreadFix may deprecate, remove, and/or reintroduce features. To view a list of feature changes please see below:
To view a complete list including prior releases, please view the 3.X Version Feature Changes list. 3.1.1April 2022
Key Updates
New/Updated API
General Improvements
Feature ChangesNote the following changes to features with the introduction of ThreadFix 3.1.1: Reintroduced
Deprecated and Removed For other REST API updates, refer to the Change Log
3.1October 2021
Key Updates
New/Updated API
General Improvements
Feature ChangesNote the following changes to features with the introduction of ThreadFix 3.1: Deprecated and Removed
Limitations, Scheduled for Enhancement Post 3.1
Absent, Scheduled for Re-introduction Post 3.1
3.0.8March 2021
Security Updates
Key Updates
General Improvements
Installation and Upgrade Guides:3.0.7October 2020 General Improvements
3.0.7 also contains the following AppSec updates. Key Updates
General Improvements
|
Table of Contents
Table of Contents |
---|