Skip to content

Releases: checkmarx-ltd/cx-flow

1.7.06

12 Dec 11:16
Compare
Choose a tag to compare

🚀 Features

🐛 Bug Fixes

  • Fixed an issue where the file cx.sarif could not be uploaded as it was not valid SARIF. @satyamchaurasiapersistent
  • Fixed a security vulnerability in CxFlow. @itsKedar
  • Fixed an issue where a comment on a PR led to an error, stating that another scan was already in progress. @satyamchaurasiapersistent
  • Fixed an issue where CxFlow was unable to create work items for ADO on-prem servers. @itsKedar
  • Fixed an issue where the CxFlow SCA scan terminated with a "Null pointer" exception. @itsKedar
  • Fixed an issue where CxFlow attempted to access a branch after a branch deletion event. @itsKedar
  • Fixed an issue where CxFlow could not set multiple project custom field values with spaces in GitHub Actions. @itsKedar

Documentation

  • Updated documentation regarding GitLab MR scan comments not reflecting the user who created the MR. @satyamchaurasiapersistent
  • Updated documentation regarding scan attempts for branches that don't match the protected branch criteria when a webhook event comes from the repository's default branch. @satyamchaurasiapersistent
  • Updated documentation for using Docker image execution, where SCA Resolver integration requires build tools installed or additional documentation. @itsKedar

1.7.05

08 Nov 09:22
26a24a0
Compare
Choose a tag to compare

🐛 Bug Fixes

1.7.04

07 Oct 10:00
1d99528
Compare
Choose a tag to compare

🚀 Features

  • Added feature to allow symbolic links in cx-flow. @itsKedar (GitHub URL : #842)
  • Added feature to add artifcat details in SAST report. @satyamchaurasiapersistent. (GitHub URL : #1252)
  • Added feature to Stack traces logged as ERROR for valid failure scenarios spam the event logs. @itsKedar (GitHub URL : #1194)
  • Added feature to support command line PR comments for Bitbucket Cloud and Bitbucket Server. @itsKedar (GitHub URL : #1125)
  • Added feature to Map labels on bug trackers like Github Issues or Gitlab Issues in Cx-Flow. @itsKedar (GitHub URL : #1029)
  • Added a feature to cancel in-progress scans in SAST if a timeout occurs. @satyamchaurasiapersistent
  • Added a feature to Configure exclude vulnerability categories in CxFlow. @itsKedar
  • Added a feature to download SCA and SAST report with critical severity in PDF report for CxFlow. @satyamchaurasiapersistent

🐛 Bug Fixes

  • Fix for Pull Request scan results should refresh after a second push to the same pull request for Cx-Flow. @itsKedar (GitHub URL : #1172)
  • Security vulnerability Fix for Cxflow. @itsKedar
  • Fix for Interactive command handling targeting the CxFlow user's name for PR workflow kickstarting. @satyamchaurasiapersistent (GitHub URL : #831)
  • Fix for removal of /cxrestapi when using checkmarx url from environment variable. @satyamchaurasiapersistent
  • Fix for custom field value with a space. @itsKedar
  • Fix for reduction of Cx-Flow messages in Pull request. @itsKedar
  • Fix for Scan was taking almost 2 hours till then some token gets expired. @itsKedar.

Documentation

Note

  • The current version of CX-Flow is experiencing issues with Azure DevOps On-Premise.

1.7.03

16 Aug 11:22
844297c
Compare
Choose a tag to compare

🚀 Features

1.7.02

05 Aug 12:10
Compare
Choose a tag to compare

🚀 Features

🐛 Bug Fixes

Documentation

  • Updated documentation for removal of JAVA support notice. @itsKedar
  • Updated support for branches in GitLab CI template. @FlorentinLedy

1.7.01

03 Jun 16:45
Compare
Choose a tag to compare

🚀 Features

🐛 Bug Fixes

Documentation

  • Updated documentation for FAQ docs for ADO work items issue. @itsKedar

1.7.0

30 Apr 09:54
60620e0
Compare
Choose a tag to compare

🚀 Features

  • Added feature to workflow change for submitting scans to avoid source location overwrite. (GH Issue URL : #1151)
  • Added feature to flow of information from JIRA to SAST.
  • Added feature to Set delete running scans as false.
  • Added feature to include folder/files that need to be scanned in Cxflow. (GH Issue URL : #1300)
  • Added new Logo of Checkmarx.
  • Added DynamoDB support for sharding in Cxflow.

🐛 Bug Fixes

  • Security vulnerability Fix for Cxflow. @itsKedar
  • Fix for SCA Project link incorrect while using ScaResolver due to concurrency issue.
  • Fix for Gitlab Bugtracker - add option to insert always new comment in mergeRequest instead of updating existing one. (GH Issue URL : #1120)
  • Fix for Branching is broken when using a project name Groovy script. (GH Issue URL : #1312)
  • Fix for Set security-severity in the SARIF SCA report to match the markdown and tags fields.
  • Fix for signed integer overflow error.

Documentation

  • Updated documentation for Add in the documentation GITLAB_ERROR_MERGE and GITLAB_BLOCK_MERGE.
  • Updated documentation for application.xml issue in root directory of project.
  • Updated documentation for cxflow variable enabled vulnerability scanner.

Support

  • Added support of springboot 3 in Cx-flow.
  • Added support for higher versions of JAVA (17,18,19,20) in cx-flow.

Note: We have stopped support of lower version of JAVA below JAVA 17.

1.6.46

29 Jan 14:41
76119ac
Compare
Choose a tag to compare

🚀 Features

🐛 Bug Fixes

  • Fix for docker badge in cxflow github repository. @itsKedar

Documentation

1.6.45

28 Nov 13:38
c48fa61
Compare
Choose a tag to compare

🚀 Features

🐛 Bug Fixes

Documentation

1.6.44

17 Oct 11:03
811db07
Compare
Choose a tag to compare

🐛 Bug Fixes
Fix for Libcurl vulnerability . @itsKedar