> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/sast-and-sca/software-updates/2022-updates.md).

# 2022

## 6 December <a href="#id-6-december" id="id-6-december"></a>

**Highlights:** support for C/C++ apps, Go updates, secrets configuration updates, SCA for containers, and the `bestfix` utility

### What's new <a href="#whats-new" id="whats-new"></a>

* C/C++: We have added beta support for the analysis of [applications written in C/C++](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/NBlD7F1DVwTeT1gds9ga).
* Go: We've updated Qwiet AI by Harness to now [support the use of Go 1.19](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/psDbThI5isUW974F5j5Y).
* Secrets: We have added granular control over how Qwiet AI by Harness scans for and identifies [secrets](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/sIl39JB7zrQrywVncz6X). You can now enable/disable the identification of secrets and set your entropy at the: [Application](https://developer.harness.io/sast-and-sca/software-updates/spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef#operation/UpdateAppConfig) level; Organization level -- you can set these values by updating your organization's [configuration as a whole](https://developer.harness.io/sast-and-sca/software-updates/spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef#operation/UpdateOrgConfig) or modifying just the [code analysis configuration settings](https://developer.harness.io/sast-and-sca/software-updates/spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef#operation/UpdateOrgAnalysisConfig).
* Software composition analysis (SCA) for containers: [SCA for containers](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/CViVopAIGnt7JCFNW3w7#sca-for-containers) is now out of beta and is generally available.
* The `bestfix` utility: We've added a [tutorial on using the bestfix script](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/tutorials/bestfix), which provides remediation and scan improvement suggestions for your application's key the Qwiet AI by Harness findings.

## 1 November <a href="#id-1-november" id="id-1-november"></a>

**Highlights:** experimental support for Razor Pages, changes to finding statuses in the dashboard

### What's new <a href="#whats-new-1" id="whats-new-1"></a>

* **Support for Razor Pages:** We're pleased to announce our experimental feature [supporting Razor Pages submitted as part of your C# project](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/6WzIytRQedLlbOKhcf2b). We currently support only `*.cshtml` files with `@page` directives, though full support for all `*.cshtml` files is forthcoming.
* **Findings status values:** We've made several changes to [how finding statuses work in the dashboard](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-details/vulnerabilities):
  * We've added an **open** status value, which indicates that you have not changed the status value of the finding. The statuses available are now: **Open**, **Fixed**, **Ignored**, **3rd Party**.
  * By default, the dashboard's findings screens (e.g., **Vulnerabilities**, **OSS Vulnerabilities**, etc.) only show findings with a status of **Open**. Any findings with a different status (**Fixed**, **Ignored**, **3rd Party**) will be hidden until you change the status value filter.

## 3 October <a href="#id-3-october" id="id-3-october"></a>

**Highlights:** required commenting, dashboard updates, JavaScript flags, C# analyses without .NET 5.0, and scan metadata

### What's new <a href="#whats-new-2" id="whats-new-2"></a>

* **Comments when setting a finding status to ignored:** We've added a check to Qwiet AI by Harness so that anyone [setting the status of a finding to ignored](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-details/vulnerabilities#expanded-details) must also add a comment to the finding that includes an explanation (this requirement applies regardless of whether you update the finding via API or the dashboard).
* **Dashboard updates**
  * **Last login timestamp:** We have updated the [Organization > Manage Users page in the dashboard](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/organizations) to display each user's Last Login information.
  * **New 3rd party finding status:** In the dashboard, you can now [set the status of findings to 3rd party](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-details/vulnerabilities#expanded-details). This allows you to indicate that the finding is in a third-party library, not your source code.
  * **Containers SCA:** The application summary and application overview on the Qwiet dashboard now display in-depth OSS information for [container vulnerabilities](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/CViVopAIGnt7JCFNW3w7).
* **JavaScript:** By default, Qwiet AI by Harness now includes HTML files in all [JavaScript analyses](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/tqRsHXiAf5jvFTWXnTCO); you can, however, disable this by including the --exclude-html flag when running sl analyze.
* **C# without .NET 5.0 runtime:** We have added instructions on [analyzing C# applications](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/6WzIytRQedLlbOKhcf2b) if you're running Qwiet AI by Harness on a machine without the required runtimes installed.
* **Scan metadata:** the Qwiet UI displays comprehensive metadata information regarding the composition of your application (if you're unfamiliar with how Qwiet defines certain concepts, please see our [metadata definitions in the documentation](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/summary)).

## 1 August <a href="#id-1-august" id="id-1-august"></a>

**Highlights:** Go 1.18, updates to build rules v2, continuous SCA, dashboard updates

### What's new <a href="#whats-new-3" id="whats-new-3"></a>

* **Go**: we have updated Qwiet Core to support the [analysis of applications written using Go 1.18](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/psDbThI5isUW974F5j5Y).
* **Build rules v2**: our [build rules v2](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/S8PQnxYOyIZVUjDZUzFp) feature now supports the use of OWASP Top 10 - 2021 tags and severity ratings based on CVSS 3.1 scores:
  * Low: 0.1-3.9
  * Medium: 4.0-6.9
  * High: 7.0-8.9
  * Critical: 9.0-10.0
* **Continuous SCA**: the [continuous SCA](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/Hhw0lWt6XweqUiOdAsVA#continuous-sca) feature alerts you regarding new OSS vulnerabilities after you've scanned your application. Qwiet monitors for the discovery and inclusion of new issues; if there are, you'll see a notification indicating such under the dashboard's OSS Vulnerabilities tab. You should then rescan your application to populate the results to the dashboard.
* **Dashboard updates**: we've updated the [Qwiet dashboard](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) with the following changes:
  * The applications overview page, which lists all of the applications associated with your org, now features graphical representations of the findings by type and severity
  * The new Organizations page allows you to see your user profile information and (if you're an admin) manage your org users and teams
  * The findings listed in the dashboard now support the use of CVSS 3.1 and OWASP Top 10 - 2021 tags.

## 12 July <a href="#id-12-july" id="id-12-july"></a>

**Highlights:** C# improvements, Kotlin improvements, dashboard updates, and updates to the VS Code extension.

### What's new <a href="#whats-new-4" id="whats-new-4"></a>

* **Analyzing C# applications**: we have updated `csharp2cpg` so that you are [no longer required to build your C# application](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/6WzIytRQedLlbOKhcf2b) before submitting it to Qwiet for analysis, though we still recommend doing so.
* **Analyzing Kotlin applications**: We have added the [following flags](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/wKN7K3UvT5BR4IbRcoE7), which you can use during the analysis of Kotlin applications:
  * `--classpath <path>`: adds a path to the classpath used by the compiler during analyses;
  * `--gradle-project-name <name>`: the Gradle configuration name to be used when downloading dependencies;
  * `--gradle-configuration-name <name>`: the Gradle project name to be used when downloading dependencies;
  * `--ignore-path <path>`: the path to add to the list of directories that Qwiet will ignore during analyses.
* **Dashboard updates**: we have updated the dashboard with the following improvements:
  * The [application summary view](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) now includes additional visual displays (e.g., additional graphs alongside numeric indicators) to streamline the presentation of your data.;
  * The [dashboard overview](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) now features two additional tabs:
    * [App Groups](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) allow you to view and manage your app groups;
    * [Teams](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) enable you to manage the teams you've created, as well as the apps and users assigned to those teams.
  * [Filtering by sources and sinks](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/finding-detail): When reviewing the data flow for individual findings, you can now select a specific source and sink to filter by; this allows you to triage vulnerabilities faster and determine which findings your code fixes would affect.
* **Updated VS Code extension**: We've updated the [VS Code extension](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/F4NmAhY6OauM6Z3jmRfj), making UI updates and adding several options to the Command Palette.

## 6 June <a href="#id-6-june" id="id-6-june"></a>

**Highlights:** custom reports, API updates, JavaScript optimization, Qwiet AI by Harness Extension for VS Code, and policy updates

### What's new <a href="#whats-new-5" id="whats-new-5"></a>

* **Custom reports when running `sl check-analysis`:** We've added [support for templates to `sl check-analysis`](broken://spaces/4t03gua31tHpZwtcczPO/pages/plcMgsqAhTtyFQ2q4RH7#custom-templates), which allows you better control how the [build rules](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/S8PQnxYOyIZVUjDZUzFp) reports this command generates appear.
* **API updates:** We have added a series of endpoints to the Qwiet API, including:
  * A series of [findings-related endpoints](https://developer.harness.io/sast-and-sca/software-updates/spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef#tag/findings) that allow users to:
    * Check a scan against a set of rules (using another scan as a reference)
    * Set the status of one or more findings
    * Set the assignee for a finding
    * Get scan information from a specific branch
  * An endpoint that returns a PCI-DSS report for a particular scan
* **JavaScript optimization:** We've added a feature that allows [JavaScript](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/tqRsHXiAf5jvFTWXnTCO) users to optimize project dependencies during transpilation (i.e., reduce dependencies to the minimal set that's required to transpile the JS/TS code), which may result in faster execution times.
* **Qwiet AI by Harness Extension for VS Code:** We are pleased to announce that our [extension for VS Code](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/F4NmAhY6OauM6Z3jmRfj) is now [available in the Visual Studio Marketplace](https://marketplace.visualstudio.com/items?itemName=Qwiet.shiftleft-core). This extension allows you to run a pre-commit check to identify secrets in your code and analyze your application for security vulnerabilities, all within your IDE.
* **Policies:** In addition to the existing default policies, we now offer [one that includes the default policy, sensitive data dictionary, and best practice guidelines](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/jH1EWj1CeHnm4NtP62jh). With this policy, Qwiet will show findings that are violations of best practices violations and attacker-reachable findings.

## 1 May <a href="#id-1-may" id="id-1-may"></a>

**Highlights:** VS Code extension, a new ability for team admins to add apps, docs for SAML/SSO integration

### What's new <a href="#whats-new-6" id="whats-new-6"></a>

* **Qwiet AI by Harness Extension for VS Code:** We are pleased to announce that our [extension for VS Code](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/F4NmAhY6OauM6Z3jmRfj) is currently in beta. This extension allows you to run a pre-commit check to identify secrets in your code and analyze your application for security vulnerabilities, all within your IDE. If you're interested in this extension, please [contact ShiftLeft](mailto:support@shiftleft.io).
* **Team admin rights:** We have updated the rights assigned to those who are team admins. Team admins can now add applications to the teams to which they are assigned; they can also move apps among their teams.
* **SAML and SSO:** If you're looking into configuring a SAML 2.0 integration so that users can log into Qwiet with single-sign on, we've [documented the end-to-end process](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/WbzXLzNYFBeWn54BTLb0).

### Reminder: ShiftLeft's domain name change <a href="#reminder-shiftlefts-domain-name-change" id="reminder-shiftlefts-domain-name-change"></a>

By 1 August 2022, we will have completed [our migration from https://www.shiftleft.io to https://app.shiftleft.io](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/H3YciBXulyJ4npUiVVUj#14-march-2022). Please ensure that your scripts, SAML/SSO configuration, and other Qwiet integrations are using the new domain.

## 1 March <a href="#id-1-march" id="id-1-march"></a>

**Highlights:** Default branches, dependencies reports, and improved scan details

### What's new <a href="#whats-new-7" id="whats-new-7"></a>

* **Default branches:** we have added the ability to [set a default branch](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) in the Qwiet Dashboard. Once a user selects a default branch, Qwiet will automatically show the user scan results from that branch instead of results from the latest scan.
* **Dependencies reporting:** with the Qwiet Dashboard, you can now obtain a [list of the libraries, packages, and external tooling used by your org's apps](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/reporting#dependencies), as well as CVE IDs to help you find information about security issues that can result from the use of the dependency.
* **Scan details:** the [scan details section of the dashboard](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview) provides information about the scan that's useful for auditing and troubleshooting/support. We've updated this portion of the dashboard to display additional information.
* **Documentation updates:** we've added several tutorials, including:
  * A walkthrough of [how to use our `/tokens` endpoints](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/MYUTXjWctt306VyVj1ES)
  * A guide on [creating service tokens for CI usage](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/pCCRYR9UJOoZ0AOZLSlA)
  * A walkthrough of [how to scan OWASP Juice Shop](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/R6qnMqEcTDFrwSqZiy5i) with Qwiet AI by Harness, which you can leverage to analyze other complex JavaScript apps

## 1 February <a href="#id-1-february" id="id-1-february"></a>

**Highlights:** SCA for Python and Go, updated build rules, additional Java support, refreshed API documentation, new access token types, Dashboard updates, and interactive remediation

### What's new <a href="#whats-new-8" id="whats-new-8"></a>

* **Intelligent SCA for Python and Go:** we are pleased to announce full [SCA support](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/Hhw0lWt6XweqUiOdAsVA) for Python applications, as well as beta support for SCA for Go packages.
* **Build Rules v2:** we have made many under-the-hood changes designed to improve the performance of our [build rules functionality](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/S8PQnxYOyIZVUjDZUzFp). However, you'll notice two things:
  * Build rules can now be used to fail builds with open-source vulnerabilities
  * You'll always see a report of the results printed whenever you execute build rules (previously, you had to pass in a `--report` flag when [running sl check-analysis](broken://spaces/4t03gua31tHpZwtcczPO/pages/plcMgsqAhTtyFQ2q4RH7) to view the report).
* **Java:** we've expanded our support of [Java applications](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/QDXGQGky0my1mQ9BJ2OC) to include those written using Java 14, 15, and 17.
* **API documentation:** we've revamped our [API documentation](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef), expanding on the endpoint descriptions, adding sample values, and linking to Postman Collections that you can use to test the endpoints.
* **Service account and CI tokens:** Qwiet now supports the [creation of Service Account tokens](https://developer.harness.io/sast-and-sca/software-updates/spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef#operation/CreateToken), which can then, in turn, be used to create [CI tokens](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/ljDHHABZubNxKPLKBkL9). The CI tokens can then be used for automated pipelines in which Qwiet runs for additional security, since they do not grant the bearer any extraneous permissions.
* **Scan details:** we've updated the dashboard to [display extended metadata regarding the scan](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-overview), which is useful for debugging and troubleshooting issues that may arise during the code scanning process.
* **Updated vulnerability descriptions:** we've improved the [vulnerability descriptions](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/finding-detail) we display to include a detailed explanation of the root cause, show developers what not to do, and why the code as-is leads to a vulnerability. The new descriptions also include actionable steps that help developers implement best practices and language-specific code samples that will eliminate the issue.
* **General dashboard updates:** we've released several improvements to the dashboard, including:
  * The ability to switch the specific branch for the application whose results you're viewing
  * Additional sorting parameters (e.g., scan time)
  * Quick links that make it easy to get in touch with our support team, talk to our sales representatives, and upgrade your Qwiet subscriptions
* **Interactive remediation:** the [interactive remediation feature](broken://spaces/4t03gua31tHpZwtcczPO/pages/axXKXndD2cEAXx8mVvKB) allows developers to declare findings and patterns that Qwiet AI by Harness should account for when analyzing code, allowing them to customize the tool as needed.
