> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/sast-and-sca/software-updates/2023-updates.md).

# 2023

## December <a href="#december" id="december"></a>

**Highlights:** general availability for Python 3.10 and later, severity for OSS findings on the applications list page

### What's new <a href="#whats-new" id="whats-new"></a>

* **General availability for Python 3.10 and later**: Support for applications written in Python 3.10 or later is now generally available. Use the `--pythonsrc` command-line flag. See [this article](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/gCjr0WN32CtaSZx3hOTf) for additional details.
* **OSS findings severities on the applications list page**: OSS findings on the applications list page now include a breakdown by severity, allowing the user to grasp the overall severity of applications findings without the need to dive deeper into the application details page.

## November <a href="#november" id="november"></a>

**Highlights:** new Qwiet AI by Harness dashboard, exclude option for PHP, and syntax highlighting for code examples

### What's new <a href="#whats-new-1" id="whats-new-1"></a>

* **Qwiet AI by Harness dashboard**: The new dashboard and landing page provides a beautiful, filterable, and interactive sankey chart that shows findings across teams, applications, and severity. It also includes a findings over time graph, and several other data points.
* **PHP exclusions**: When analyzing a PHP application, you can now exclude files and directories. Use the `--exclude` or `--exclude-regex` options.
* **Syntax highlighting for code examples**: Code examples found in findings descriptions and other parts of the Qwiet AI by Harness web console now include syntax highlighting. This makes the code easier to read and follow, in order to understand the finding and possible solutions faster.

## October <a href="#october" id="october"></a>

**Highlights:** updates to C#, auto-language detection and project name inferences, and resetting personal access tokens

### What's new <a href="#whats-new-2" id="whats-new-2"></a>

* **C#**: Qwiet AI by Harness now supports using full *and* relative file paths when [users submit the --ignore-project flag](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/6WzIytRQedLlbOKhcf2b) to exclude projects from the scan.
* **Auto-language detection and project name inference**: When using the `sl analyze` command, you no longer have to include the project name or language; Qwiet AI by Harness will auto-detect both pieces of information from your project. That is, `sl analyze --app AppName --python <path/to/code>` becomes `sl analyze <path/to/code>`. See [Your first code analysis](broken://spaces/uPVBkglG6gsk2SsnsKgG/pages/TttvRsX00hNaoDKOB7NC) for additional information.
* **Reset personal access tokens**: Users can now [reset their personal access tokens](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/ljDHHABZubNxKPLKBkL9).

## September <a href="#september" id="september"></a>

**Highlights:** updates to Go, Python, SBOM export, Docker image, and UI

### What's new <a href="#whats-new-3" id="whats-new-3"></a>

* **Go**: Qwiet AI by Harness now supports the [analysis of applications written in Go 1.21](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/psDbThI5isUW974F5j5Y).
* **Python**: Users submitting [applications written in Python 3.10 (or later)](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/gCjr0WN32CtaSZx3hOTf) can have Qwiet AI by Harness ignore specific file paths and directories during code analysis.
* **SBOM export**: We have updated the [SBOM](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/mpma1Zcf9db4BGR2dLlM) that Qwiet AI by Harness generates for your application to include the number of exploitable CVEs.
* **Docker image for Qwiet AI by Harness integration**: We have released a [Docker](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/sb8NTKPOknpYkKJ7hXLm) image compatible with machines built on ARM64 architecture.
* **Qwiet AI by Harness UI**: Our [updated UI](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/W7Ymzt7BLnNU4xbNeNv2) is now generally available; at this time, all users will be migrated to the UI, and the classic UI is no longer available.

## August <a href="#august" id="august"></a>

**Highlights:** security issues, support for ASP.NET apps, improved secrets detection, SBOM exports, updated Qwiet AI by Harness UI, Qwiet the Noise

### What's new <a href="#whats-new-4" id="whats-new-4"></a>

* **Security issues**: Qwiet AI by Harness now displays [security issues](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/mViluSuefL7gTs42ki42) for every application you submit for analysis. These findings are instances of problematic code in applications that help you identify bad practices and potential problems that could result in vulnerabilities. These issues may not currently affect the security of your application, but they could become problematic in the future. Qwiet AI by Harness enables security issues for new accounts, but admins can enable this feature for existing users under org settings.
* **Support for ASP.NET Core apps**: Qwiet AI by Harness is now compatible with [apps using the ASP.NET Core framework](broken://spaces/uPVBkglG6gsk2SsnsKgG/pages/0c1ezDgaUil5NxR4VnY3).
* **Secrets detection**: Qwiet AI by Harness has improved its [secrets](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/sIl39JB7zrQrywVncz6X) detection functionality; it no longer treats data structures as sensitive if one of the fields/members are deemed sensitive. Instead, Qwiet AI by Harness tracks the sensitive fields/member, resulting in fine-grained results and fewer false positives.
* **SBOM exports**: For each application submitted to Qwiet AI by Harness, you can [export the SBOM](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/reporting) generated by Qwiet AI by Harness in various standards and formats, including CycloneDX and SPDX.
* **Updated Qwiet AI by Harness UI**: We have released a [new design for the Qwiet AI by Harness UI](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/W7Ymzt7BLnNU4xbNeNv2)! You can now choose between the existing interface and the newly released one. Click **Try our new design** on the bottom-right of the UI to try out the new design. Return to the current version at any time by clicking **Back to the classic design**.
* **Qwiet the Noise**: we've introduced a [Qwiet the Noise](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/3cRycyfUVL61FeVbrM1l) button, which can help you focus on the most pressing issues. Toggling this button on applies the following filters:
  * Vulnerabilities: filters for vulnerabilities of critical or high severity;
  * OSS vulnerabilities: filters for OSS vulnerabilities of critical or high severity that are also reachable and exploitable.

You can find the Qwiet the Noise button by opening up your application and going to **Findings** > **Vulnerabilities** (or **OSS Vulnerabilities**). The toggle is next to the filters.

## July <a href="#july" id="july"></a>

**Highlights:** CWE reports, new features for analysis of C# application

### What's new <a href="#whats-new-5" id="whats-new-5"></a>

* **CWE report:** Qwiet AI by Harness now [generates a CWE report](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/reporting) every time you submit an application for analysis. The CWE report displays a complete list of the CWEs present in your application and the associated findings that introduce the issue. In addition to viewing the report in the Qwiet AI by Harness dashboard, you can export it in PDF or HTML.
* **Identification of C# licenses:** The Qwiet AI by Harness licensing detection feature now [supports the detection of licenses used in NuGet packages](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/6WzIytRQedLlbOKhcf2b) to help you manage the legal risks regarding your OSS package/library usage.
* **Ignoring C# projects in scans:** When submitting a C# application for analysis, you can [use the --ignore-project flag](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/6WzIytRQedLlbOKhcf2b) to exclude one or more associated projects (e.g., test projects) from being scanned and improve the performance of Qwiet AI by Harness.

## June <a href="#june" id="june"></a>

**Highlights:** new support for PHP, OSS licensing information and checks in build rules, and EPSS score and exploitability status filters

### What's new <a href="#whats-new-6" id="whats-new-6"></a>

* **PHP**: We are pleased to announce beta support for [applications written using PHP](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/TmBkUZtZnqCPk7UFhXNh).
* **OSS licensing information**: Qwiet AI by Harness now includes detailed licensing information in the SBOM it generates to help you manage the legal risks regarding your OSS package/library usage. You can view the licensing information for the OSS packages leveraged by your application in the [SBOM report or via API](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/gsONNIRkYvShD8tpP8Ga).
* **Licensing checks in build rules**: We've updated our build rules features so that you can write [build rules that check the licenses used](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/S8PQnxYOyIZVUjDZUzFp); if a developer uses a package with a licensing model that introduces a conflict given how you bring your application to market, the build will fail.
* **Filtering by EPSS score**: When reviewing scan results yielding OSS vulnerabilities in the Qwiet AI dashboard, you can [filter based on a finding's EPSS score](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/oss-vulnerabilities).
* **Filtering by exploitability status**: You can [filter OSS vulnerability findings using the exploitability filter](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/oss-vulnerabilities); this allows you to identify findings with known exploits and those with no known exploits.

## May <a href="#may" id="may"></a>

**Highlights:** new application reporting features, expanded support for Python applications, and the launch of Qwiet AI Services

### What's new <a href="#whats-new-7" id="whats-new-7"></a>

* **Application Reporting**: We have introduced a [dedicated reporting section](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/reporting) for each application you submit for analysis by Qwiet AI. This section allows you to view the software bill of materials (SBOM), view and download OWASP 2021 and OWASP 2017 information for your application, and download a report to check your application's compliance with PCI DSS requirements.
* **Python**: We are pleased to announce beta support for applications written using [Python 3.10 and later](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/gCjr0WN32CtaSZx3hOTf).

## April <a href="#april" id="april"></a>

**Highlights:** Blacklight, OWASP reports via API, CVSS filtering, improvements to the `bestfix` script, and updates to our docs site

### What's new <a href="#whats-new-8" id="whats-new-8"></a>

* **Blacklight**: Qwiet AI's new [Blacklight](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/ui-v1/application-details/oss-vulnerabilities#exploits-blacklight) feature shows you up-to-date OSS vulnerability information, including those found in your containers. For each identified vulnerability, Qwiet AI displays the dates the vulnerability was reported, the source providing a proof of concept of the exploit, and the availability of the exploit (e.g., public, private, or commercial). The dashboard also shows the vulnerability's Exploit Prediction Score System (EPSS) score, helping you focus on findings with high EPSS and CVSS scores.
* **OWASP reports via API**: You can now [obtain a copy of your OWASP report](https://developer.harness.io/sast-and-sca/software-updates/spaces/lJyA24omPa8yzz8MNf2k/pages/czxq1Lp10NxpqGdkmJef#tag/reports/operation/ReadDetailedOWASPReport) (in either HTML or PDF format) via the Qwiet AI API.
* **CVSS filtering**: When reviewing [OSS vulnerabilities](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/oss-vulnerabilities) (including those for [containers](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/dashboard/application-details/container)), you can filter for issues by setting the CVSS score range. The dashboard will then display all issues whose score falls into the set range. This feature is under Advanced Filters.
* **Update to the `bestfix` utility**: We've updated [our `bestfix` utility](https://app.gitbook.com/s/lJyA24omPa8yzz8MNf2k/sast/tutorials/bestfix), which provides remediation and scan improvement suggestions for your application's key the Qwiet AI by Harness findings, to print PDF reports for your convenience.
* **Updated documentation**: We have refreshed [our docs site](https://docs.shiftleft.io/). In addition to updated styling, we have fixed and improved the search feature, fixed usage issues (including, but not limited to, those involving code blocks, navigation bars, and text displays), improved navigation markers, and launched a mobile-friendly version of the site.

## February <a href="#february" id="february"></a>

**Highlights:** ShiftLeft CORE is now Qwiet AI Qwiet AI by Harness, updated support for applications written in C# and Python

### What's new <a href="#whats-new-9" id="whats-new-9"></a>

* **ShiftLeft is now QwietAI**: We are pleased to announce that [ShiftLeft is now QwietAI](https://qwiet.ai/lets-make-some-noise-for-qwiet-ai-stuart-mcclure-qwiet-ai-ceo/), reflecting our product's ability to reduce noise for your AppSec and DevSecOps teams and allowing them to focus on the results that matter the most to your application's security. We've also changed the name of our platform to Qwiet AI by Harness. This name better reflects the preventative nature of the work we help you do: finding zero-day and pre-zero-day vulnerabilities.
* **AI learning**: Qwiet AI by Harness now features [AI-powered detection of vulnerabilities](broken://spaces/lJyA24omPa8yzz8MNf2k/pages/2YMnqOPBgGFHki7mw2if) in your Java code. Our security researchers generate policy definitions, using knowledge from Qwiet AI by Harness machine learning model to help define rules and dynamic policies. The model focuses especially on your in-house or custom third-party libraries. Qwiet AI by Harness then tags these vulnerabilities for review on the dashboard.
* **Updated C# support**: We have [updated our support for applications written in C#](broken://spaces/uPVBkglG6gsk2SsnsKgG/pages/0c1ezDgaUil5NxR4VnY3#language-specific-requirements) to include those written using C# 11.
* **Updated Python support**: We have [updated our Python support](broken://spaces/uPVBkglG6gsk2SsnsKgG/pages/0c1ezDgaUil5NxR4VnY3) to include applications written using Python 3.9 and earlier.
