Skip to main content

Supply Chain Security release notes

These release notes describe recent changes to Harness Supply Chain Security.

About Harness Release Notes
  • Progressive deployment: Harness deploys changes to Harness SaaS clusters on a progressive basis. This means that the features described in these release notes may not be immediately available in your cluster. To identify the cluster that hosts your account, go to your Account Overview page in Harness. In the new UI, go to Account Settings, Account Details, General, Account Details, and then Platform Service Versions.
  • Security advisories: Harness publishes security advisories for every release. Go to the Harness Trust Center to request access to the security advisories.
  • More release notes: Go to Harness Release Notes to explore all Harness release notes, including module, delegate, Self-Managed Enterprise Edition, and FirstGen release notes.

November 2024

Version: 1.19.1

New features and enhancements

  • Launched a dedicated SLSA Generation step under the Supply Chain Security section in the step palette; removed the SLSA Provenance section from the stage Overview. You can now perform SLSA provenance generation and attestation using the new SLSA Generation step.
  • Chain of Custody in the Artifact section now logs events from the Security Testing Orchestration (STO) module.
  • Rule Definitions section now has an expandable view, showing rule descriptions upon expansion; replaced the Type column with Applicable On to display the entity types to which rules apply, such as Code Repository or CI/CD, along with platform/Integration logo. For example, GitHub, GitHub Actions.
Enhancements in CI/CD section
  • Added sorting option for pipelines based on Risk and Compliance Issues column.
  • New filter for pipelines by CI/CD Types, allowing you to list GitHub workflows or Harness pipelines.
Enhancements in Compliance section
  • Renamed Rules tab to Evaluations.
  • Added Applicable On column in the Evaluations tab to display the entity types to which rules apply, such as Code Repository or CI/CD.
  • Added a link to entity source in the impacted entity details within the Evaluations tab. By clicking on an impacted entity, you can use the “Go to workflow/repository” link to navigate directly to the associated pipeline or repository.

October 2024

Version: 1.18.0

New features and enhancements

  • Added rule 2.3.9 from OWASP CICD-SEC-6 for evaluation against Harness pipelines. For more information, refer to the Standards and Rule Definitions documentation.
  • In the Evaluation details, links to the relevant GitHub workflows or Harness pipelines have been included.
  • Introduced UI enhancements in the Compliance section.

July 2024

Version: 1.14.3

Announcements

SCS is now Generally Available (GA). We have moved from Limited GA (since January 2024) to GA. Read more on our announcement blog.

New features

  • Repository Security Posture Management:
    • Connect your GitHub with Harness SCS to identify insecure configurations in code repositories and organization settings for comprehensive risk, compliance, and security posture management. Use the Harness SCS GitHub app for integration. Learn more in our RSPM documentation.
  • Manage Risk and Compliance
  • Integrations and Permissions

Enhancements

Artifact view will now support the following views

  • Chain of Custody: Log the artifact's journey throughout the software supply chain.
  • Artifact Listing: View all container images, including their digests and tags.
  • Security Insights: Access detailed information on security vulnerabilities.
  • SLSA Provenance: View the provenance and verification status of artifacts following the SLSA framework.

July 2024

Version 1.12.0

New features and enhancements

  • The "Repositories" tab previously located in the Artifact View has been relocated and expanded into a separate section titled "Code Repositories". All repository data will now be accessible from the Code Repositories section, providing a more streamlined interface for managing repository information.

September 2023

The Supply Chain Security module documentation is live on the Harness Developer Hub. Check back soon for module release notes.