Changelog
Follow up on the latest improvements andΒ updates.
RSS
π New Features
- Implemented webhook for issues
- Implemented a filter by repository for dashboard main dashboard graph
- Enriched finding details with additional information
π Enhancements
- GitLab connector options format panel
- Improved notification data display
- Added per-tool severity filter for tools connector
π§ Integrations
- Microsoft Marketplace submission approved for Plexicus
π New Features
- Microsoft Marketplace integrationis now available, including subscription support.
- Total Finding Graphscan be filtered from selected repositories.
- Create Remediationsupportedtimeout handlingfor more reliable processing.
- Google authenticationnow supports terms & conditions display after register for first time.
- Introducing Trial planswill be the default plan for users.
π Enhancements
- Optimized sidebar behaviorandbanner stylingfor better navigation.
- Updated layout visualsfor login and error screens.
- Smoother tab component stylingfor improved UI consistency.
- Better error handlingacross payment flows and remediation systems.
- Updated project ID handlingfor GitLab plugin integrations.
π Compliance & Customization
- Adjusted subscription flow logicfor more accurate behavior when switching plans.
- Added validation and expiration fieldsfor free-to-trial upgrades, only valid for 30 days after user registered.
- Expanded support for self-hosted GitLab URLs.
π§ Integrations
- Checkmarx integrationis now supported.
- GitLab authorization scopesand plugin systems have been improved.
π New Features
- GitLab Self-Hosted Enhancements
- Gitea Connector Enhancements
- Prowler Integration (Initial & Full Implementation)
- DAST Connector Implementation
- Email Reminder for Not Setup Accounts
π Enhancements
- Bitbucket Workflow Action Setup Functions
- Checkov & KICS Category Division
- Partnership Enhancements
- Flow WebSocket on Setup Pipeline
- Enhancement for OpenAI Connection
π Compliance & Customization
- Remediation & Workflow Execution Fixes
- Security & Dependabot Vulnerabilities Resolved
- Nuclei Tool Exclusion for Default Users
π§ Integrations
- Fixes for Findings & Validation Tools
- Token Refresh & API Issues (GitLab, OpenAI, Workers, Repository Management)
- Worker Timeout & API Stability Improvements
- Cronjob Fixes & Logging Enhancements
π New Features
- Partner Collection: We've introduced a new feature to manage and organize partner data.
- OCSF Field: A new OCSF field has been added to enhance how findings are tracked.
- Customizable Reasoning Effort: Now you can customize the reasoning effort settings across the platform.
- Prowler Integration: We've fully integrated Prowler, a new tool to improve security scanning.
- DAST Integration: DAST (Dynamic Application Security Testing) is now part of the platform, allowing more detailed security analysis.
- Account Setup Reminder: A helpful email reminder is now sent to users who haven't set up their accounts yet.
- GitLab Self-Hosted Support: You can now integrate GitLab self-hosted repositories for security scanning.
- Websocket Support for Pipelines: We've improved the pipeline setup process by adding websocket support.
- Enhanced Partnership Management: New improvements have been made to manage and configure partnerships more easily.
π Enhancements
- Better Organization for Checkov & KICS: We've broken down Checkov and KICS into smaller, more manageable categories for easier navigation.
- Increased Timeout for Workers: Workers now have more time to process tasks, ensuring smoother operations.
- Schedule Reminder: Cronjob for reminder have been enhanced for better reliability in scheduled tasks.
- Improved Gitea Connector: Gitea connector has been upgraded to include additional features.
- Updated Pricing Flow: We've made changes to the subscription payment process, including updates to the Stripe integration.
π Compliance & Customization
- Partner: Added a new way to manage different partner types, including commercial and free options.
- Prevention of Duplicate Reminders: We've added safeguards to stop the same reminder email from being sent multiple times.
- Cloud Connector Improvements: Cloud deployment connectors have been enhanced for more reliable integration.
π§ Integrations
- OpenAI Connection Fixes: We've improved the OpenAI integration and resolved connection issues to ensure seamless functionality.
- DAST & Nuclei Security Scans: Added support for DAST and Nuclei for more thorough security testing.
- GitLab Action Integration: GitLab actions are now integrated for automated security checks and workflows.
- Bitbucket Fixes: Fixed issues with Bitbucket, ensuring smoother operation.
π New Features
- Added support for BlackDuck and fixed import-related issues.
- Prioritized mandatory policies over best practices in findings management.
- Introduced multiple tokens for the Plexalyzer connector.
- Superadmin can now manage clients directly.
- Integrated Azure Insights instrumentation for better monitoring.
- CVSS score now displayed using a radar view.
- Separated Trivy into 4 distinct categories for better organization.
π Enhancements
- Improved handling of findings creation of status not enriched
- Applied enriched filters to all findings in downloads.
- Enhanced UI elements for better clarity in finding details.
- Improved the formatting of subscription start and end dates.
- Updated login background image for a refreshed look.
- Optimized the dashboard by ensuring only one date filter is used.
π Compliance & Customization
- Enforced subscription restrictions in the upload scan workflow.
- Adjusted worker permissions and cronjob configurations.
- Updated pricing information for better transparency.
π§ Integrations
- Fixed issues with the BlackDuck importer and updated client data.
- Resolved token parameter issues for Gitea repositories.
- Improved SCM pipeline status tracking.
- Added BlackDuck upload scan support.
π Enhancements
- Improved the Finding Validation prompt for better accuracy.
- Possible refinements in the policy AI enrichment process.
π Compliance & Customization
- Updated NIST guidelines to align with updated requirements.
π§ Integrations
- Disabled and added Black Duck connectors for improved integration handling.
π New Features
- Workflow Variables and Secrets for Gitea: Added functions to create workflow variables and secrets for Gitea.
- Gitea Workflow Actions: Implemented workflow action content specific to Gitea.
- Bulk Actions for Remediations and PRs: Introduced bulk actions functionality for remediations and PRs.
- Historical Graph Collection Updates: Automatic updates for the Historical Graph collection.
- SCM Security Connector: Added a new connector category for SCM Security.
- KICS Connector Integration: Moved the KICS connector into CI/CD Posture.
- Gitea Integration: Added Gitea as a new SCM connector, including API service, branch/repository interfaces, token management, and flow integration.
π Enhancements
- Findings Chart Calculation: Improved how findings chart results are calculated.
- Validation Enhancements: Better input validation for Gitea URLs.
- Subscription Plan UI Updates: Added extra information and smoother flows for pricing and subscription plans.
- Payment Card Component: Introduced a payment card component with added usage and pricing details.
- Improved Auto Scan Flow: Enhanced the automatic scan and validation process for findings.
- Gitea Modal Interface: Added a close button for connector modal and better flow management for repository selection.
- Organization Wizard UI: Hid the map component in the organization structure wizard for cleaner UI.
π Compliance & Customization
- API Key Cloud Input: Updated with an asterisk indicator for required fields.
- Banner Pricing: Enhanced compliance with interval pricing and subscription banners for better clarity.
- Inactive Subscription Middleware: Added middleware to manage actions for inactive subscriptions.
π§ Integrations
- Stripe Integration:
- Added a new service for Stripe API.
- Integrated pricing and subscription flows with card payment and plan banners.
- Improved payment card components for readonly and advanced pricing plans.
- Gitea Continuous Integration:
- Improved flow for connecting, managing, and deleting Gitea repositories.
- Updated cache and websocket handling for repository updates.
- Improved test connection functionality for hosted and cloud domains.
- Fixed token configuration issues for SCM connectors.
π New Features
- Plan & Pricing Updates
- Added new plans and pricing tiers to unlock more features and provide greater flexibility for Plexicus users.
- Autonomous Scanning Support
- Plexicus now supports autonomous scans, enabling continuous monitoring without manual intervention.
- Standalone Plexalyzer Enhancements
- Plexalyzer now supports commands from JSON input and includes new output formats: pretty and serif.
- Stripe Payment Integration
- Payments are now seamless and secure with Stripe, simplifying your subscription experience.
π Enhancements
- Webhook Update: Receive Issue Closures
- Improved webhook functionality to automatically handle notifications for issue closures in real time.
- Email Verification Expiration Update
- Enhanced email verification process by extending expiration times for greater usability.
- Subfindings for Library Updates
- Automatically generate subfindings for updated libraries, allowing detailed tracking of vulnerabilities tied to parent findings.
- Multiple Filter Values on Findings
- Apply multiple filter values to findings for a more flexible and streamlined search experience.
- Automatic Pull Requests for False Positives
- Marking a finding as a false positive now triggers an automatic pull request with comments to exclude the finding.
π Compliance & Customization
- Expanded Regulation Support for AI Validation
- Plexicus now includes additional regulations for AI validation and supports more customizable regulation settings.
π§ Integrations
- Automated Pipeline Configuration for GitHub
- Plexicus now supports automatic configuration of pipeline integrations in GitHub, saving you time and effort.
Now Plexicus supports cloud scanning to detect findings related to cloud missconfigurations. Currently we support:
- Amazon AWS
- Microsoft Azure
- Google Cloud Platform
- Oracle Cloud