Designed for high availability. Horizontal scalability, distributed work queues, and the option to separate
web and worker nodes. No single point of failure, and no additional infrastructure requirements outside the
PostgreSQL database you already have.
Resiliency as a first-class citizen. Durable execution guarantees that background work such as BOM processing,
vulnerability analysis, and notifications completes even through node restarts and crashes.
New powerful CEL-based policy engine, providing more flexibility while being more efficient
than the engine shipped with v4. Policies can be complex, don't let rigid UI conditions limit you.
Automatic portfolio-wide vulnerability analysis. Leverage the new policy engine to audit
and suppress vulnerabilities before they surface in the UI or trigger notifications.
Component integrity verification. Detect components whose hashes don't match what's published in package
repositories.
Centralized secrets management. Manage credentials for integrations securely in one place.
The Findings response object's vulnerability will no longer contain two fields below, cwes will hold the respective ids.
cweId
cweName
In the SARIF file (schema defined in sarif.peb), cweId will be replaced by list of cwe ids in cwes. And name of the SARIF rule will be vulnerability's vulnId instead of cweName.
The /api/v1/finding/project/{uuid} REST API endpoint now supports pagination
apiserver/#1111. The page size defaults to 100.
Clients currently expecting all items to be returned at once must be updated to deal with pagination.