Skip to main content

Checkmarx SCA Release Notes July 2023

Notice

These release notes relate to the SCA standalone product. Users who consume SCA through Checkmarx One should refer to the Checkmarx One release notes to see which SCA features have been released in Checkmarx One.

Warning

The IgnoreVulnerability and UnignoreVulnerability APIs, which had been used for triaging SCA vulnerabilities, will be deprecated on July 7. They have been replaced by the new Management of Risk API, which supports applying any Checkmarx One state and adding comments. We recommend migrating to the new API well in advance of the July 7 deadline.

Improvements and Bug Fixes

Status

Item

Description

UPDATE

SBOM

We added two optional query parameters to the POST /export API, hideDevAndTestDependencies and showOnlyEffectiveLicenses. These can be used to filter the results returned in the SBOM report.

SCA Resolver Releases

We released the following new versions of SCA Resolver:

Notice

The complete changelog, and links to download SCA Resolver are available here.

Version 2.2.11

  • Fixed a bug related with exploitable path that the file was being generated in an incorrect format.

Version 2.2.9

  • Improved file handling of large results files.

  • For PIP, Graphviz is now used instead of the pipdeptree tool.