Skip to main content

Upcoming Multi-Tenant Version | 3.64

Warning

The content and dates of these Release Notes are provisional and subject to change.

All new features, enhancements, and resolved issues will be available upon version deployment in the multi-tenant environment unless explicitly stated otherwise in the respective section's subheading.

New Features and Enhancements

Added Column Management to Risk Orchestration

The Risk Orchestration table now supports column management across SAST, SCA, IaC, DAST, Containers, and Secrets. You can show or hide columns, reorder them via drag-and-drop, and filter or sort by any column, with your preferences saved for future sessions.

Since engines expose different columns, shared columns stay consistent across engines while engine-specific columns remain available for deeper context. This gives teams a more tailored view of risk data that better fits their workflow.

Improved AI-BOM Export in Global Inventory

AI-BOM export from Global Inventory now runs through the unified reporting pipeline for a more consistent, reliable experience. You can trigger the export as before and download it once it's ready.

This ensures dependable exports, even for large inventories.

Manual Risk Triage via MCP Server

You can now triage SAST and SCA risks directly through the MCP Server, without opening Checkmarx One. Using your AI assistant, you can update a risk's state, such as marking it Confirmed or Not Exploitable, add a comment, and view its triage history within your existing workflow.

This lets teams review and remediate risks faster, without switching context between tools.

Included BYOR Results in Analytics and Reports

Scan results from imported BYOR files are now included in analytics and reports, alongside results from standard scans. This data is available wherever project or application-level reports are generated.

As a result, reports reflect a complete and consistent view of all scan results, regardless of how they were produced.

IaC

The IaC version included in this release of Checkmarx One is 2.1.20.

IaC updates are documented in the IaC changelog.

DAST

Guided Scans Now Display Recording Errors

Guided scan results now show errors from the recordings used in a scan, so you can see which recordings failed and why. This also shows how each recording affected scan coverage - including any additional paths or vulnerabilities it uncovered.

Custom Attributes for Uploaded API Scan Files

You can now define additional attributes when uploading an API file for scanning. Add key/value variables to Postman files, set a Target URL for OpenAPI/Swagger, or an Endpoint for GraphQL schemas.

This is especially helpful when a file's paths are relative and don't specify a host. Once saved, uploaded files show an icon indicating extra attributes are attached, with options to edit or delete them.

Resolved Issues

Item

Description