> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/release-notes/software-supply-chain-assurance.md).

# Supply Chain Security release notes

These release notes describe recent changes to Harness Supply Chain Security.

{% hint style="info" %}
**ABOUT HARNESS RELEASE NOTES**

* **Progressive deployment:** Harness deploys changes to Harness SaaS clusters on a progressive basis. This means that the features described in these release notes may not be immediately available in your cluster. To identify the cluster that hosts your account, go to your **Account Overview** page in Harness. In the new UI, go to **Account Settings**, **Account Details**, **General**, **Account Details**, and then **Platform Service Versions**.
* **Security advisories:** Harness publishes security advisories for every release. Go to the [Harness Trust Center](https://trust.harness.io/?itemUid=c41ff7d5-98e7-4d79-9594-fd8ef93a2838\&source=documents_card) to request access to the security advisories.
* **More release notes:** Go to [Harness Release Notes](/release-notes/readme.md) to explore all Harness release notes, including module, delegate, Self-Managed Enterprise Edition, and FirstGen release notes.
  {% endhint %}

### July 2026 <a href="#july-2026" id="july-2026"></a>

#### Version: v1.65.0 , Plugin Version: v0.65.0 <a href="#version-v1650-plugin-version-v0650" id="version-v1650-plugin-version-v0650"></a>

**New Features and Enhancements**

* Added support for [AI Bill of Materials (AIBOM)](/software-supply-chain-assurance/use-scs/open-source-management/generate-aibom-for-repositories.md), enabling visibility into AI-related components such as models, datasets, agents, libraries, and frameworks used within source repositories through structured AIBOM generation in CycloneDX format.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-84130228ad772ead661517a194fc39e05f63203d%2Faibom-generation.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [Resource Groups for Supply Chain Security](/software-supply-chain-assurance/troubleshooting-and-resources/settings-1/rbac.md#create-a-new-resource-group), enabling administrators to manage access to SCS resources through configurable resource groups at the Account, Organization, and Project scopes.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-dcc3a6e8f587a797ed282bba8f99aa8761b0f9e8%2Fresource-group-selection.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [GitLab CI/CD integration](/software-supply-chain-assurance/use-scs/open-source-management/sbom-gitlab-ci-cd.md), enabling teams to integrate Harness SCS into GitLab workflows to generate and ingest SBOMs, enforce SBOM policies, generate and verify SLSA provenance, and sign and verify software artifacts.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-8a3360a6607fad29506e5b1efad89605d44ede86%2Fgitlab-integration.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Artifact Registry (AR) integration for [artifact signing](/software-supply-chain-assurance/use-scs/artifact-security/sign-verify/sign-artifacts.md#container-images) and [verification](/software-supply-chain-assurance/use-scs/artifact-security/sign-verify/verify-signed-artifacts.md#container-images) steps is now **Generally Available (GA)**.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-8ecadaf39f4de57ca5820cbad84abd7e1fb881d8%2Fartifact-registry-signing.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>

**Fixed Issues**

* Fixed an issue where Repository Security Posture Management (RSPM) APIs did not consistently enforce role-based access control (RBAC) across project, organization, and account scopes, allowing unauthorized access in certain scenarios.
* Fixed an issue where SBOM orchestration could fail to extract tool information from CycloneDX SBOMs generated by JFrog Xray, preventing successful SBOM processing.
* Fixed an issue where intermittent failures in SBOM Policy Enforcement and SLSA verification could cause pipeline executions to fail unexpectedly ([ZD-120518](https://harnesssupport.zendesk.com/agent/tickets/120518)).

### June 2026 <a href="#june-2026" id="june-2026"></a>

#### Version: v1.64.0 , Plugin Version: v0.63.0 <a href="#version-v1640-plugin-version-v0630" id="version-v1640-plugin-version-v0630"></a>

**New Features and Enhancements**

* Added support for [evaluating security settings inherited from GitHub organizations and accounts](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md#supported-standards-and-rules) during Repository Security Posture Management (RSPM) compliance scans, reducing false positives in repository compliance results.

### May 2026 <a href="#may-2026" id="may-2026"></a>

#### Version: v1.62.3 , Plugin Version: v0.61.0 <a href="#version-v1623-plugin-version-v0610" id="version-v1623-plugin-version-v0610"></a>

**New Features and Enhancements**

* Added support for [Role-Based Access Control (RBAC) for Supply Chain Security](/software-supply-chain-assurance/troubleshooting-and-resources/settings-1/rbac.md), enabling granular access management for SCS workflows across Account, Organization, and Project scopes through configurable role-based permissions. This feature is behind the feature flag `SCS_RBAC` for existing accounts.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-7b035738aa9cc2b24a9965de1afbd1647b783714%2Faccess-control-permissions.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [Bitbucket Repository Onboarding in RSPM](/software-supply-chain-assurance/use-scs/open-source-management/integrations/bitbucket.md), allowing you to discover, onboard, and manage Bitbucket repositories directly within SCS.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-58ddbb43c2095078d08debfb31a144e9ce60e9fe%2Fbitbucket-integration.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for detecting dependencies with [malicious packages](/software-supply-chain-assurance/use-scs/risk-and-compliance/opensource-security-risk-management.md#malicious-packages) and [typosquatting](/software-supply-chain-assurance/use-scs/risk-and-compliance/opensource-security-risk-management.md#typosquatting) OSS risks, helping identify potentially deceptive or harmful open-source dependencies. You can filter dependencies by these risk types, review detailed risk summaries, and use the detected risk counts in pipeline policies to strengthen software supply chain security.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-7dde88156e4e28e890b0a4e953ed0dd5dd78fbeb%2Fmalicious-package-typosquatting-ossrisks.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [License Family Classification](/software-supply-chain-assurance/use-scs/open-source-management/license-family.md) in Software Bill of Materials (SBOM), enabling automatic categorization of licenses into license families for improved license risk assessment and governance. This feature also supports custom license family mappings and policy-based enforcement using OPA policies.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-9673beffd2a0c847d263a41d2d89c306ba9316eb%2Flicense-family-configuration.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>

**Breaking Changes**

* With the general availability of [Role-Based Access Control (RBAC) for Supply Chain Security](/software-supply-chain-assurance/troubleshooting-and-resources/settings-1/rbac.md), users assigned view-only roles can no longer perform write operations on SCS resources unless explicitly granted the required permissions.

**Fixed Issues**

* Fixed an issue where SBOM orchestration steps could fail during SBOM upload when custom configuration settings were not applied correctly, resulting in connectivity issues ([ZD-112588](https://harnesssupport.zendesk.com/agent/tickets/112588)).

### April 2026 <a href="#april-2026" id="april-2026"></a>

#### Version: v1.59.0 , Plugin Version: v0.59.0 <a href="#version-v1590-plugin-version-v0590" id="version-v1590-plugin-version-v0590"></a>

**New Features and Enhancements**

* Added support for [OSS risks remediation](/software-supply-chain-assurance/use-scs/open-source-management/oss-risks-remediation.md), enabling intelligent upgrades of vulnerable open-source dependencies with recommended versions that reduce risk while minimizing breaking changes.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-b02ad313b7f376b96b9b675b4a3b884cfbf36477%2Foss-remediation-rl.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [SLSA provenance generation for non-container artifacts](/software-supply-chain-assurance/use-scs/artifact-security/slsa/generate-slsa.md#non-container-artifacts), allowing verification of how artifacts are built and ensuring consistent traceability and integrity across formats such as Java packages, Helm charts, and native binaries.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-99ac4126721e20e3c9df50695e55ec13036a97e6%2Fgenerate-slsa-non-container-image.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [keyless signing](/software-supply-chain-assurance/use-scs/artifact-security/slsa/generate-slsa.md#attest-slsa-provenance) and [verification](/software-supply-chain-assurance/use-scs/artifact-security/slsa/verify-slsa.md#verify-slsa-attestation) using OIDC-based identity, removing the need to manage long-lived cryptographic keys. It supports AWS, GCP, and Azure OIDC providers and works across SCS workflows, including artifact signing, SBOM, and SLSA attestation and verification.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-70a53cc9e9386ebda0771f06477d677c2c082441%2Fattest-slsa-keyless.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Added support for [cdxgen CLI flags](/software-supply-chain-assurance/use-scs/open-source-management/generate-sbom-for-artifacts.md#use-cdxgen) to customize SBOM generation across scan scope, dependency resolution, and output behavior.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-fb319b005d91c2d9d87555d678386f5b45461c44%2Fcli-flags-sbom.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>

**Fixed Issues**

* Fixed an issue where Artifact Verification stage templates could fail validation and display errors in YAML view when opened or recreated from the UI ([ZD-111043](https://harnesssupport.zendesk.com/agent/tickets/111043)).
* Fixed an issue where SBOM, Artifact Signing, and SLSA Generation steps could fail with permission errors in Kubernetes-based workflows due to environment variables not being propagated correctly in Kubernetes execution ([ZD-111326](https://harnesssupport.zendesk.com/agent/tickets/111326)).

### March 2026 <a href="#march-2026" id="march-2026"></a>

#### Version: v1.57.0 , Plugin Version: v0.57.0 <a href="#version-v1570-plugin-version-v0570" id="version-v1570-plugin-version-v0570"></a>

**New Features and Enhancements**

* Added support for a [dependency table](/software-supply-chain-assurance/use-scs/open-source-management/direct-indirect-dependency.md#viewing-the-dependency-table) to show direct and indirect dependencies for any dependency within a repository.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-7e09b371f832ab0cf41c47095e901cae7702a950%2Fdependency-graph-for-dependency.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Removed the `Supplier` column and its filter from the SBOM overview tab. The `Supplier` field is now shown in the SBOM overview panel.
* OWASP scans in the default RSPM pipeline may fail when OSS Index authentication is not configured. To prevent this issue, either configure OSS Index authentication using the `--ossIndexUsername` and `--ossIndexPassword` flags, or disable OSS Index using the `--disableOssIndex` flag and rely on NVD for vulnerability data ([ZD-110388](https://harnesssupport.zendesk.com/agent/tickets/110388)).

### February 2026 <a href="#february-2026" id="february-2026"></a>

#### Version: 1.52.0 , Plugin Version: 0.53.0 <a href="#version-1520-plugin-version-0530" id="version-1520-plugin-version-0530"></a>

**New Features and Enhancements**

* Filtering SBOM components by [Dependency Type](/software-supply-chain-assurance/use-scs/open-source-management/direct-indirect-dependency.md#filtering-directindirect-dependencies) (Direct, Indirect, No Relationship) for code repositories is now **Generally Available (GA)**. This feature was behind the feature flag `SCS_DEPENDENCY_SEGREGATION`.

**Fixed Issues**

* Fixed an issue where the SLSA generation step could fail when a container image was provided without a tag. The step now correctly defaults to `latest` when no tag is specified ([ZD-106153](https://harnesssupport.zendesk.com/agent/tickets/106153)).

### January 2026 <a href="#january-2026" id="january-2026"></a>

#### Version: 1.50.0 , Plugin Version: 0.52.0 <a href="#version-1500-plugin-version-0520" id="version-1500-plugin-version-0520"></a>

**New Features and Enhancements**

* Added support to filter SBOM components by [Dependency Type](/software-supply-chain-assurance/use-scs/risk-and-compliance/repository-security-posture-management-rspm.md#sbomsoftware-bill-of-materials-tab) (Direct, Indirect, No Relationship) for code repositories, enabling classification based on how each component is related in the SBOM and improving component-level traceability across the project. This feature is behind the feature flag `SCS_DEPENDENCY_SEGREGATION`. Contact [Harness Support](mailto:support@harness.io) to enable this feature.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-7e329d1ac69b02bc5c9ee207c2342f2e441a815f%2Fdependency-graph-analysis.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>
* Extended SBOM vulnerability support to all STO scanners (previously limited to Snyk and Trivy). The SBOM page now displays vulnerabilities identified by any STO scanner.

  If the STO license is not enabled, dependency vulnerabilities are mapped from the Harness internal database. If you have an STO license and want to map the vulnerabilities from the Harness internal database, contact [Harness Support](mailto:support@harness.io) to enable this feature.
* Added `Docker:Dind` base image support to ensure SCS plugin compatibility with Docker v29 and later versions ([ZD-103871](https://harnesssupport.zendesk.com/agent/tickets/103871)).

**Fixed Issues**

* Fixed an issue where the OSS Risks – `Known Vulnerabilities in dependencies` filter on the SBOM page was not working as expected.
* Fixed an issue where CD events were missing from the Chain of Custody during artifact redeployments. Events are now properly captured and displayed, ensuring complete traceability.
* Fixed an issue where the SBOM count displayed on the Overview page did not match the count shown in the SBOM tab.
* Fixed an issue in the [SBOM Score API](https://apidocs.harness.io/sbom/getsbomscoreforartifact) to correctly generate the SBOM score when the repository name is provided with the `https://` prefix.

### November 2025 <a href="#november-2025" id="november-2025"></a>

#### Version: 1.46.10 , Plugin Version: 0.50.0 <a href="#version-14610-plugin-version-0500" id="version-14610-plugin-version-0500"></a>

**New Features and Enhancements**

* We have pinned our Harness SCS plugins to use Docker API version `1.41`, which is supported by Docker engine versions `20.10` – `28.0`. Docker engine versions 29 and above are not supported as it require a newer Docker API version `1.44` that the plugins do not support. As a result, all SCS plugin versions will fail if Docker 29 or later is used.
* If you use `docker:dind` as the image, it pulls Docker Engine version 29, which relies on Docker API version `1.44` that all plugins do not support and as a result, all SCS plugin versions will fail. Make sure to use `docker:28-dind` as the image to resolve the issue.
* Added extended [Java support in cdxgen](/software-supply-chain-assurance/use-scs/open-source-management/generate-sbom-for-repositories.md#configure-cdxgen-with-extended-java-support) to properly handle `JAVA_HOME` error ([ZD-96323](https://harnesssupport.zendesk.com/agent/tickets/96323)), ([ZD-91015](https://harnesssupport.zendesk.com/agent/tickets/91015)).

**Fixed Issues**

* Fixed search bar responsiveness and image layer filter visibility.
* Fixed inconsistent HAR artifact names across all SCS steps

### October 2025 <a href="#october-2025" id="october-2025"></a>

#### Version: 1.43.0 , Plugin Version: 0.48.0 <a href="#version-1430-plugin-version-0480" id="version-1430-plugin-version-0480"></a>

**New Features and Enhancements**

* Added a new api to fetch the `integration id`.

```
curl --location 'https://app.harness.io/gateway/ssca-manager/v1/orgs/<ORG-NAME>/projects/<PROJECT-NAME>/integration/integration-summary?github_org_url=<GITHUB_ORG_URL>' \ --header 'x-api-key: <X-API-KEY>'
```

* In the SBOM Orchestration step, now you can [enforce an OPA policy](/software-supply-chain-assurance/use-scs/risk-and-compliance/opensource-security-risk-management.md#enforce-policy) to block pipelines that include End of Life (EOL) components based on their count.

**Fixed Issues**

* Fixed an issue where STO results were not showing up in the Artifact page and the chain of custody.
* Added support to handle registry URLs that include port information (e.g., `nexus.example.com:7991/repository/group/repo`).
* Fixed the intermittent SBOM failure caused by Cosign timeout ([ZD-93784](https://harnesssupport.zendesk.com/agent/tickets/93784)).
* Added support to map vulnerability data for non-container artifacts.
* Enabled routing to specific SCS step through the **View Pipeline Execution** links in the chain of custody.
* Fixed **unsupported manifest errors** while fetching image digests in the SBOM Orchestration step ([ZD-92970](https://harnesssupport.zendesk.com/agent/tickets/92970,), [ZD-92711](https://harnesssupport.zendesk.com/agent/tickets/92711)).
* Added RBAC support for secrets referenced in the SCS steps to ensure pipelines fail when the secrets are inaccessible. This is behind FF `SSCA_RBAC_CHECK_SECRETS`.

### September 2025 <a href="#september-2025" id="september-2025"></a>

#### Version: 1.41.0 , Plugin Version: 0.45.0 <a href="#version-1410-plugin-version-0450" id="version-1410-plugin-version-0450"></a>

**New Features and Enhancements**

* [SBOM ingestion of non-container artifacts](/software-supply-chain-assurance/use-scs/open-source-management/ingest-sbom-data.md#non-container-images), the artifact path is now optional, allowing ingestion to be performed directly from the provided SBOM file. This makes it easier to manage artifact paths at scale.
* Added support to manage the [OWASP Top 10 risks](/software-supply-chain-assurance/use-scs/risk-and-compliance/opensource-security-risk-management.md), enables you to easily identify outdated, unmaintained, close to end of life, and end of life components, and create Jira ticket to update package version.

  <figure><img src="https://530581648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdSRdIerXDmqsO6h9KZy%2Fuploads%2Fgit-blob-6cf605c13c94ec017581314233ed58eeb9fb4f00%2Freleasenotes.png?alt=media" alt=""><figcaption><p>Click to view full size image</p></figcaption></figure>

**Fixed Issues**

* Fixed the search filters for code repositories and licenses on the SBOM page, which were previously not working accurately.
* The total vulnerabilities count on the code repository page is now the exact sum of critical, high, medium, and low severity issues (previously, info-level issues were also included).
* Fixed a Go-GitHub package parsing issue in GitHub Enterprise URLs ([ZD-92576](https://harnesssupport.zendesk.com/agent/tickets/92576)).

### August 2025 <a href="#august-2025" id="august-2025"></a>

#### Version: 1.39.0 , Plugin Version: 0.44.0 <a href="#version-1390-plugin-version-0440" id="version-1390-plugin-version-0440"></a>

**New features and enhancements**

* Added support for [Ingestion of SBOM for non-container artifacts](/software-supply-chain-assurance/use-scs/open-source-management/ingest-sbom-data.md#non-container-images).
* Added support for secure connect for all the SCS plugins ([ZD-87724](https://harnesssupport.zendesk.com/agent/tickets/87724)).
* SBOM score for an artifact can now be downloaded via [API](https://apidocs.harness.io/sbom/getsbomscoreforartifact).

**Fixed Issues**

* Artifact signing step was not working in air-gap mode. Support for Rekor in `air-gapped` mode has been added.
* SBOM orchestration for the code repos via syft used to show the source type as `file` not it is updated to `application`.

### July 2025 <a href="#july-2025" id="july-2025"></a>

#### Version: 1.36.0 , Plugin Version: 0.42.0 <a href="#version-1360-plugin-version-0420" id="version-1360-plugin-version-0420"></a>

**New features and enhancements**

* Added support for AWS authentication - Assume IAM Role with delegate and IRSA, enabling compatibility with environments that restrict the use of AWS secret access keys.

**Fixed Issues**

* Fixed an issue where the [Delete Repos API on the repo listing page](https://apidocs.harness.io/tag/Delete-Repositories#operation/deleteRepositories) deleted all branches in the repository, even when a specific branch was provided. It now deletes only the specified branch. ([ZD-88336](https://harnesssupport.zendesk.com/agent/tickets/88336))
* Fixed `unsupported manifest format` error by dynamically fetching the architecture from the stage infrastructure at runtime instead of using a hardcoded value. ([ZD-86959](https://harnesssupport.zendesk.com/agent/tickets/86959))

#### Version: 1.34.5 , Plugin Version: 0.40.0 <a href="#version-1345-plugin-version-0400" id="version-1345-plugin-version-0400"></a>

**New features and enhancements**

* The [SBOM tab](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#sbom-tab) now displays component-level vulnerabilities by mapping STO Snyk scan results to SBOM components.
* Two new dashboards are now available:
  * [Component Violations for Artifacts and Code Repositories](/software-supply-chain-assurance/use-scs/dashboards-and-reports/component-violations.md) to flag pipelines for SBOM violations across repositories in different projects.
  * [Component Summary for Artifacts and Code Repositories](/software-supply-chain-assurance/use-scs/dashboards-and-reports/component-summary.md) to display all unique components across artifacts and repositories within your account
* SBOM now uses the repository name as the default application name. To override this and use `/harness` as the application name, set the stage variable `SYFT_SBOM_NO_SOURCE_NAME=TRUE`. ([ZD-87366](https://harnesssupport.zendesk.com/agent/tickets/87366))

**Fixed Issues**

* Fixed an issue where updating the integration to include all repositories still showed only the previously selected ones.
* Fixed an issue where STO container scan results (e.g., JFrog Xray) were not mapped to Artifact SBOM vulnerabilities due to a case mismatch. Now it has been updated to ensure accurate vulnerability mapping. ([ZD-84700](https://harnesssupport.zendesk.com/agent/tickets/84700))
* Fixed an issue where component searches returned incomplete results. Search is now consistent across all projects and organizations, improving visibility. ([ZD-84422](https://harnesssupport.zendesk.com/agent/tickets/84422))

### June 2025 <a href="#june-2025" id="june-2025"></a>

#### Version: 1.33.0 , Plugin Version: 0.39.1 <a href="#version-1330-plugin-version-0391" id="version-1330-plugin-version-0391"></a>

**New features and enhancements**

* Registry domain URLs for artifacts stored in Docker registries, including GCR, ECR, ACR, JFrog Self-Hosted (On-Prem), and Kubernetes registries (Self-Hosted), no longer need to be specified, as the domain is already included in the connector URL. In all SCS steps, only the image name is required.
* Removed delegate selectors as a mandatory field from the API configuration for setting up the VM infra in [RSPM pipeline infra](https://apidocs.harness.io/tag/PipelineInfraConfig) configuration.([ZD-81509](https://harnesssupport.zendesk.com/agent/tickets/81509))
* For SBOM Drift, the **Detect drift from baseline** option has been removed from the SBOM orchestration step for artifacts.

**Fixed Issues**

* Fixed an issue where dependency searches across projects were incomplete, making it hard to assess zero-day attacks.([ZD-84422](https://harnesssupport.zendesk.com/agent/tickets/84422))

### May 2025 <a href="#may-2025" id="may-2025"></a>

#### Version: 1.31.0 <a href="#version-1310" id="version-1310"></a>

**New features and enhancements**

* SLSA generation and verification steps now support both image tag and digest, enhancing traceability and artifact integrity validation across pipelines.

  **Note**: When modifying the existing SLSA steps, you must manually remove the digest from the YAML configuration to ensure compatibility with the updated functionality.
* Added [API support](https://apidocs.harness.io/tag/Integration-Step-Config) for the VM to configure step resources and settings (e.g., syft, cdxgen, CycloneDX, SPDX) at the account, org, or project level.
* Added support for Vault integration in Harness Cloud to securely manage secrets during pipeline executions.

**Fixed Issues**

* Fixed a bug where the license filters (e.g., contains, starts with) were not functioning as expected on the Artifacts page (SCS-3308).
* Fixed an issue where manually edited and saved integrations were skipping their scheduled next Iterations.This has been resolved by updating next Iterations upon manual edits. ( [ZD-82987](https://support.harness.io/hc/en-us/requests/82987), [ZD-83068](https://support.harness.io/hc/en-us/requests/83068)) (SCS-3708).
* Resolved issue where repositories onboarded via API were not being displayed on the integration page (SCS-3642).
* Fixed issue in the SBOM Orchestration step where, if an image name included a digest, the Supply Chain tab and Artifacts page displayed the digest in the corresponding tag field(SCS-3675).

### April 2025 <a href="#april-2025" id="april-2025"></a>

#### Version: 1.29.0 <a href="#version-1290" id="version-1290"></a>

**New features and enhancements**

* Artifact signing and verification steps now support non-container artifacts (such as Helm charts, JARs, WARs, and manifest files) enhancing artifact integrity and security before deployment.
* Added [API support](https://apidocs.harness.io/tag/Integration-Step-Config) to configure step resources and settings (e.g., syft, cdxgen, CycloneDX, SPDX) at the account, org, or project level, with options to run steps in parallel or sequentially.
* Registry domain URLs for artifacts stored in JFrog - Artifactory Cloud (Saas) and Kubernetes registries (cloud-hosted) no longer need to be specified, as the domain is already included in the connector URL. In all SCS steps only the image name is required.

Example:

JFrog: `</your-repo/test-image>:tag`

**Fixed Issues**

* Resolved an issue where signing an artifact using image name and digest created a new entry with an `@sha256` suffix instead of updating the existing entry (SCS-3404).
* Fixed a bug where the Delete Integration API responded with 200 OK even for invalid integration IDs; it now returns an appropriate error (SCS-3339).
* Fixed artifact verification failures caused by `signatureId` being overwritten during the verification step, causing the system to look for signature files in the wrong location (SCS-3509 , ZD-78728).
* Resolved CDXgen failures in restricted clusters by modifying the plugin to run in air-gapped mode, eliminating the need for external license fetch calls (SCS-3590).

### February 2025 <a href="#february-2025" id="february-2025"></a>

#### Version: 1.25.1 <a href="#version-1251" id="version-1251"></a>

**New features and enhancements**

* Added [Dashboards for License and Compliance Reports](/software-supply-chain-assurance/use-scs/dashboards-and-reports/view-licenses.md) to easily access detailed information about the licenses and compliance status associated with your software components at one place.
* Added [Artifact Signing and Verification](/software-supply-chain-assurance/use-scs/artifact-security/sign-verify/sign-artifacts.md) steps to sign artifacts and verify the signed artifacts before it gets deployed to ensure integrity and prevent tampering.
* With Harness Internal Developer Portal (IDP) workflow now you can use a single GitHub connector at the account level and selectively onboard repositories to the project of your choice and automatically create scan pipelines to scan those repositories.
* Secure attestation with Cosign using HashiCorp Vault, now supported via Vault Proxy with GCP Auth for enhanced security.
* Enabled SBOM and SLSA generation and verification via Harness GitHub Actions, integrating seamlessly with GitHub CI workflows.

**Fixed Issues**

* Added a link in the Supply Chain tab that redirects to the Artifacts/Repositories details page, for better traceability.
* Fixed the issue where clicking the back button on the Select Code Repo page after selecting a connector redirected the user to the login page.

### November 2024 <a href="#november-2024" id="november-2024"></a>

#### Version: 1.19.1 <a href="#version-1191" id="version-1191"></a>

**New features and enhancements**

* Launched a dedicated **SLSA Generation** step under the Supply Chain Security section in the step palette; removed the **SLSA Provenance** section from the stage Overview. You can now perform SLSA provenance generation and attestation using the new SLSA Generation step.
* [Chain of Custody](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#chain-of-custody) in the Artifact section now logs events from the Security Testing Orchestration (STO) module.
* [Rule Definitions](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md) section now has an expandable view, showing rule descriptions upon expansion; replaced the **Type** column with **Applicable On** to display the entity types to which rules apply, such as Code Repository or CI/CD, along with platform/Integration logo. For example, GitHub, GitHub Actions.

**Enhancements in CI/CD section**

* Added sorting option for pipelines based on **Risk and Compliance Issues** column.
* New filter for pipelines by **CI/CD Types**, allowing you to list GitHub workflows or Harness pipelines.

**Enhancements in Compliance section**

* Renamed **Rules** tab to **Evaluations**.
* Added **Applicable On** column in the **Evaluations** tab to display the entity types to which rules apply, such as Code Repository or CI/CD.
* Added a link to entity source in the [impacted entity details](/software-supply-chain-assurance/use-scs/risk-and-compliance/manage-compliance-posture.md#view-impacted-entities) within the **Evaluations** tab. By clicking on an impacted entity, you can use the “Go to workflow/repository” link to navigate directly to the associated pipeline or repository.

### October 2024 <a href="#october-2024" id="october-2024"></a>

#### Version: 1.18.0 <a href="#version-1180" id="version-1180"></a>

**New features and enhancements**

* Added rule `2.3.9` from [OWASP CICD-SEC-6](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md#cicd-sec-6-insufficient-credential-hygiene) for evaluation against Harness pipelines. For more information, refer to the [Standards and Rule Definitions](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md) documentation.
* In the Evaluation details, links to the relevant GitHub workflows or Harness pipelines have been included.
* Introduced UI enhancements in the Compliance section.

### July 2024 <a href="#july-2024" id="july-2024"></a>

#### Version: 1.14.3 <a href="#version-1143" id="version-1143"></a>

**Announcements**

**SCS is now Generally Available (GA)**. We have moved from Limited GA (since January 2024) to GA. Read more on our [announcement blog](https://www.harness.io/blog/harness-ssca-now-features-repo-security-posture-management-rspm).

**New features**

* **Repository Security Posture Management**:
  * Connect your GitHub with Harness SCS to identify insecure configurations in code repositories and organization settings for comprehensive risk, compliance, and security posture management. Use the [Harness SCS GitHub app](https://github.com/apps/harness-ssca) for integration. Learn more in our [RSPM](/software-supply-chain-assurance/use-scs/risk-and-compliance/repository-security-posture-management-rspm.md) documentation.
* **Manage Risk and Compliance**
  * **Compliance Section**: A new Compliance section to assess and understand the risk posture of your entire supply chain. Detailed information is available in the [Manage Compliance Posture](/software-supply-chain-assurance/use-scs/risk-and-compliance/manage-compliance-posture.md) documentation.
  * **Rule Definitions Section**: Access a complete list of all standards and associated rules supported by Harness SCS, including:

    * [CIS Benchmarks for GitHub](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md#cis-benchmarks)
    * [OWASP Top 10 CI/CD Risks for GitHub](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md#owasp-top-10-cicd-security-risks)

    More details can be found in the [Standards and Rule Definitions](/software-supply-chain-assurance/use-scs/risk-and-compliance/standards-and-rule-definitions.md) documentation.
* **Integrations and Permissions**
  * A new interface to manage your integrations with Harness SCS. Learn more about this in the Integrations and Permissions.

**Enhancements**

[Artifact view](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#view-your-artifacts) will now support the following views

* [Chain of Custody](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#chain-of-custody): Log the artifact's journey throughout the software supply chain.
* [Artifact Listing](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#digests-for-your-artifact): View all container images, including their digests and tags.
* [Security Insights](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#vulnerabilities-tab): Access detailed information on security vulnerabilities.
* [SLSA Provenance](/software-supply-chain-assurance/use-scs/artifact-security/overview.md#view-your-artifacts): View the provenance and verification status of artifacts following the SLSA framework.

### July 2024 <a href="#july-2024" id="july-2024"></a>

#### Version 1.12.0 <a href="#version-1120" id="version-1120"></a>

**New features and enhancements**

* The "Repositories" tab previously located in the [Artifact View](/software-supply-chain-assurance/use-scs/artifact-security/overview.md) has been relocated and expanded into a separate section titled "[Code Repositories](https://developer.harness.io/docs/software-supply-chain-assurance/code-repositories-view)". All repository data will now be accessible from the [Code Repositories](https://developer.harness.io/docs/software-supply-chain-assurance/code-repositories-view) section, providing a more streamlined interface for managing repository information.

### September 2023 <a href="#september-2023" id="september-2023"></a>

The [Supply Chain Security module documentation](https://app.gitbook.com/s/SN2B2M5cFWy0hhD0xTuE/README) is live on the Harness Developer Hub. Check back soon for module release notes.
