Changelog

Follow up on the latest improvements andΒ updates.

RSS

πŸš€ New Features
  • Implemented webhook for issues
  • Implemented a filter by repository for dashboard main dashboard graph
  • Enriched finding details with additional information
πŸ›  Enhancements
  • GitLab connector options format panel
  • Improved notification data display
  • Added per-tool severity filter for tools connector
πŸ”§ Integrations
  • Microsoft Marketplace submission approved for Plexicus
πŸš€ New Features
  • Microsoft Marketplace integration
    is now available, including subscription support.
  • Total Finding Graphs
    can be filtered from selected repositories.
  • Create Remediation
    supported
    timeout handling
    for more reliable processing.
  • Google authentication
    now supports terms & conditions display after register for first time.
  • Introducing Trial plans
    will be the default plan for users.
πŸ›  Enhancements
  • Optimized
    sidebar behavior
    and
    banner styling
    for better navigation.
  • Updated
    layout visuals
    for login and error screens.
  • Smoother
    tab component styling
    for improved UI consistency.
  • Better
    error handling
    across payment flows and remediation systems.
  • Updated
    project ID handling
    for GitLab plugin integrations.
πŸ“‹ Compliance & Customization
  • Adjusted
    subscription flow logic
    for more accurate behavior when switching plans.
  • Added
    validation and expiration fields
    for free-to-trial upgrades, only valid for 30 days after user registered.
  • Expanded support for
    self-hosted GitLab URLs
    .
πŸ”§ Integrations
  • Checkmarx integration
    is now supported.
  • GitLab authorization scopes
    and plugin systems have been improved.
πŸš€ New Features
  • GitLab Self-Hosted Enhancements
  • Gitea Connector Enhancements
  • Prowler Integration (Initial & Full Implementation)
  • DAST Connector Implementation
  • Email Reminder for Not Setup Accounts
πŸ›  Enhancements
  • Bitbucket Workflow Action Setup Functions
  • Checkov & KICS Category Division
  • Partnership Enhancements
  • Flow WebSocket on Setup Pipeline
  • Enhancement for OpenAI Connection
πŸ“‹ Compliance & Customization
  • Remediation & Workflow Execution Fixes
  • Security & Dependabot Vulnerabilities Resolved
  • Nuclei Tool Exclusion for Default Users
πŸ”§ Integrations
  • Fixes for Findings & Validation Tools
  • Token Refresh & API Issues (GitLab, OpenAI, Workers, Repository Management)
  • Worker Timeout & API Stability Improvements
  • Cronjob Fixes & Logging Enhancements
πŸš€ New Features
  • Partner Collection: We've introduced a new feature to manage and organize partner data.
  • OCSF Field: A new OCSF field has been added to enhance how findings are tracked.
  • Customizable Reasoning Effort: Now you can customize the reasoning effort settings across the platform.
  • Prowler Integration: We've fully integrated Prowler, a new tool to improve security scanning.
  • DAST Integration: DAST (Dynamic Application Security Testing) is now part of the platform, allowing more detailed security analysis.
  • Account Setup Reminder: A helpful email reminder is now sent to users who haven't set up their accounts yet.
  • GitLab Self-Hosted Support: You can now integrate GitLab self-hosted repositories for security scanning.
  • Websocket Support for Pipelines: We've improved the pipeline setup process by adding websocket support.
  • Enhanced Partnership Management: New improvements have been made to manage and configure partnerships more easily.
πŸ›  Enhancements
  • Better Organization for Checkov & KICS: We've broken down Checkov and KICS into smaller, more manageable categories for easier navigation.
  • Increased Timeout for Workers: Workers now have more time to process tasks, ensuring smoother operations.
  • Schedule Reminder: Cronjob for reminder have been enhanced for better reliability in scheduled tasks.
  • Improved Gitea Connector: Gitea connector has been upgraded to include additional features.
  • Updated Pricing Flow: We've made changes to the subscription payment process, including updates to the Stripe integration.
πŸ“‹ Compliance & Customization
  • Partner: Added a new way to manage different partner types, including commercial and free options.
  • Prevention of Duplicate Reminders: We've added safeguards to stop the same reminder email from being sent multiple times.
  • Cloud Connector Improvements: Cloud deployment connectors have been enhanced for more reliable integration.
πŸ”§ Integrations
  • OpenAI Connection Fixes: We've improved the OpenAI integration and resolved connection issues to ensure seamless functionality.
  • DAST & Nuclei Security Scans: Added support for DAST and Nuclei for more thorough security testing.
  • GitLab Action Integration: GitLab actions are now integrated for automated security checks and workflows.
  • Bitbucket Fixes: Fixed issues with Bitbucket, ensuring smoother operation.
πŸš€ New Features
  • Added support for BlackDuck and fixed import-related issues.
  • Prioritized mandatory policies over best practices in findings management.
  • Introduced multiple tokens for the Plexalyzer connector.
  • Superadmin can now manage clients directly.
  • Integrated Azure Insights instrumentation for better monitoring.
  • CVSS score now displayed using a radar view.
  • Separated Trivy into 4 distinct categories for better organization.
πŸ›  Enhancements
  • Improved handling of findings creation of status not enriched
  • Applied enriched filters to all findings in downloads.
  • Enhanced UI elements for better clarity in finding details.
  • Improved the formatting of subscription start and end dates.
  • Updated login background image for a refreshed look.
  • Optimized the dashboard by ensuring only one date filter is used.
πŸ“‹ Compliance & Customization
  • Enforced subscription restrictions in the upload scan workflow.
  • Adjusted worker permissions and cronjob configurations.
  • Updated pricing information for better transparency.
πŸ”§ Integrations
  • Fixed issues with the BlackDuck importer and updated client data.
  • Resolved token parameter issues for Gitea repositories.
  • Improved SCM pipeline status tracking.
  • Added BlackDuck upload scan support.
πŸ›  Enhancements
  • Improved the Finding Validation prompt for better accuracy.
  • Possible refinements in the policy AI enrichment process.
πŸ“‹ Compliance & Customization
  • Updated NIST guidelines to align with updated requirements.
πŸ”§ Integrations
  • Disabled and added Black Duck connectors for improved integration handling.
πŸš€ New Features
  • Workflow Variables and Secrets for Gitea: Added functions to create workflow variables and secrets for Gitea.
  • Gitea Workflow Actions: Implemented workflow action content specific to Gitea.
  • Bulk Actions for Remediations and PRs: Introduced bulk actions functionality for remediations and PRs.
  • Historical Graph Collection Updates: Automatic updates for the Historical Graph collection.
  • SCM Security Connector: Added a new connector category for SCM Security.
  • KICS Connector Integration: Moved the KICS connector into CI/CD Posture.
  • Gitea Integration: Added Gitea as a new SCM connector, including API service, branch/repository interfaces, token management, and flow integration.
πŸ›  Enhancements
  • Findings Chart Calculation: Improved how findings chart results are calculated.
  • Validation Enhancements: Better input validation for Gitea URLs.
  • Subscription Plan UI Updates: Added extra information and smoother flows for pricing and subscription plans.
  • Payment Card Component: Introduced a payment card component with added usage and pricing details.
  • Improved Auto Scan Flow: Enhanced the automatic scan and validation process for findings.
  • Gitea Modal Interface: Added a close button for connector modal and better flow management for repository selection.
  • Organization Wizard UI: Hid the map component in the organization structure wizard for cleaner UI.
πŸ“‹ Compliance & Customization
  • API Key Cloud Input: Updated with an asterisk indicator for required fields.
  • Banner Pricing: Enhanced compliance with interval pricing and subscription banners for better clarity.
  • Inactive Subscription Middleware: Added middleware to manage actions for inactive subscriptions.
πŸ”§ Integrations
  1. Stripe Integration:
  • Added a new service for Stripe API.
  • Integrated pricing and subscription flows with card payment and plan banners.
  • Improved payment card components for readonly and advanced pricing plans.
  1. Gitea Continuous Integration:
  • Improved flow for connecting, managing, and deleting Gitea repositories.
  • Updated cache and websocket handling for repository updates.
  • Improved test connection functionality for hosted and cloud domains.
  • Fixed token configuration issues for SCM connectors.
πŸš€ New Features
  1. Plan & Pricing Updates
  • Added new plans and pricing tiers to unlock more features and provide greater flexibility for Plexicus users.
  1. Autonomous Scanning Support
  • Plexicus now supports autonomous scans, enabling continuous monitoring without manual intervention.
  1. Standalone Plexalyzer Enhancements
  • Plexalyzer now supports commands from JSON input and includes new output formats: pretty and serif.
  1. Stripe Payment Integration
  • Payments are now seamless and secure with Stripe, simplifying your subscription experience.
πŸ›  Enhancements
  1. Webhook Update: Receive Issue Closures
  • Improved webhook functionality to automatically handle notifications for issue closures in real time.
  1. Email Verification Expiration Update
  • Enhanced email verification process by extending expiration times for greater usability.
  1. Subfindings for Library Updates
  • Automatically generate subfindings for updated libraries, allowing detailed tracking of vulnerabilities tied to parent findings.
  1. Multiple Filter Values on Findings
  • Apply multiple filter values to findings for a more flexible and streamlined search experience.
  1. Automatic Pull Requests for False Positives
  • Marking a finding as a false positive now triggers an automatic pull request with comments to exclude the finding.
πŸ“‹ Compliance & Customization
  1. Expanded Regulation Support for AI Validation
  • Plexicus now includes additional regulations for AI validation and supports more customizable regulation settings.
πŸ”§ Integrations
  1. Automated Pipeline Configuration for GitHub
  • Plexicus now supports automatic configuration of pipeline integrations in GitHub, saving you time and effort.
Now Plexicus supports cloud scanning to detect findings related to cloud missconfigurations. Currently we support:
  • Amazon AWS
  • Microsoft Azure
  • Google Cloud Platform
  • Oracle Cloud