8
1.0.35
Zurich, Yokohama, Xanadu, Washington DC, Vancouver, Utah
Checkmarx One Vulnerability Integration uses data imported from Checkmarx One Service to help determine the impact and priority of vulnerabilities in the code as well as its dependencies.
Version 1.0.15 and above will have DevOps Integration support.
This integration imports SAST, SCA, IaC, Container Security, API Security, Secret Detection and ScoreCard results from the Checkmarx One platform.
Checkmarx One Vulnerability Integration – Version 1.0.35 Enhancements
The 1.0.35 release will includes the following features and improvements:
- Application Details in ServiceNow:
Application Name and Application ID associated with projects will now appear in the Source Additional Info field within the Discovered Applications table in ServiceNow. - Primary Branch Scan Import Option:
A new option has been added to the Scan Synchronization dropdown on the Configuration page, allowing the import of scans/results from only the primary branch of Project. - Closure of Findings for Deleted Projects:
When the Close findings on deleted Projects setting is enabled, AVITs will be marked as Closed for any projects deleted in CxOne, regardless of the integration start time. - Enhanced Project Filtering:
Filter by Project now supports importing more than 1,000 projects when the entered substring matches over 1,000 projects in CxOne. - Accurate Closed Vulnerability Counts:
The Checkmarx One AVIT Closure Integration will now display the updated item count for closed vulnerabilities in the Integration Run section. - Precise Import Metrics for AVIT Integration:
The Checkmarx One Application Vulnerability Item Integration will report only the number of findings inserted or updated in the AVIT table. - Expanded Logging:
Diagnostic and configuration logs have been added to improve troubleshooting and visibility. - Updated Result State Field:
The Result State field has been updated to a field-type input where users can directly enter the states that should be filtered. - Integration Start-Time Reliance:
The Checkmarx One Application Vulnerability Item Integration will now rely on the integration’s Start Time specified during execution, rather than the AVIT updated time in ServiceNow.
-
-
Install the pre-requisite plugins in the following order (mentioned is minimum supported version for X,Y,Z release)
- security integration framework (13.10.6)
- security support common (13.18.1)
- Security Support Orchestration (12.13.2)
- Vulnerability Response Dependencies
- Vulnerability Response (26.0.13)
-