> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/sast-and-sca/prezero/product-information/advisories.md).

# Advisories

## 14 March 2022 <a href="#id-14-march-2022" id="id-14-march-2022"></a>

We're in the process of migrating the Qwiet application domain from `https://www.shiftleft.io` to `https://app.shiftleft.io`. The Qwiet website, however, will remain at `https://www.shiftleft.io`.

With this change, we will be able to provide you with increased security and performance.

You can begin using `https://app.shiftleft.io` today. We will support the use of both domains through **1 August 2022**; at that point, you must use `https://app.shiftleft.io` for Qwiet AI by Harness.

### What this change means for Qwiet users <a href="#what-this-change-means-for-qwiet-users" id="what-this-change-means-for-qwiet-users"></a>

Due to the updated domain name, you may need to make the following changes:

* Update any old `sl` binaries that might be using `https://www.shiftleft.io`
* Update your firewalls; see our [updated list of URLs](/sast-and-sca/prezero/deployment/deployment.md#configure-your-firewall) that you should allowlist
* Update any scripts calling Qwiet URLs (e.g., scripts calling the Qwiet API, any Terraform modules you use to deploy Qwiet AI by Harness)
* Update your SAML/SSO configuration

Please ensure that you've updated the domain name by **1 August 2022**. We recommend that you implement any necessary changes and test before the changeover date.

## 25 October 2021 <a href="#id-25-october-2021" id="id-25-october-2021"></a>

Our research team has learned that the `ua-parser-js` package has been compromised with malicious code by threat actors. The versions affected include:

* `pkg:npm/ua-parser-js@0.7.29`
* `pkg:npm/ua-parser-js@0.8.0`
* `pkg:npm/ua-parser-js@1.0.0`

You can read more of our research in [this article](https://blog.shiftleft.io/evolving-threat-series-infiltrating-npms-supply-chain-ua-parser-js-356cd50ec527).

As of 25 October 2021, a review of dependencies used by active I-SCA customers shows that none of the applications scanned by Qwiet AI by Harness are using affected versions of `ua-parser-js`.

### Recommendations <a href="#recommendations" id="recommendations"></a>

* Avoid upgrading or rolling back to the affected versions of `ua-parser-js`.
* [Scan your applications](/sast-and-sca/prezero/oss-vulnerabilities.md) to generate a new SBoM and check for the versions listed above.
