Kondukto Release v1.106 24th Sep, 2025

Kondukto v1.106 released!

New Features:

  • Added Invicti Unified Platform integration with support for project listing, profiles, and scan creation.
  • Added Mend SAST integration with project retrieval and scan support
  • Added Azure OpenAI support as a new LLM provider.
  • Added source code–based API endpoint discovery with SAST linkage.
  • Added CVSS Vector field to optional parameters in issue assignment settings.
  • Added ability to link vulnerabilities to existing issues at product and global levels (previously only available at project level).

Improvements:

  • Added meta titles across all pages
  • Updated design of sidebar and login page.
  • Removed direct dependency restriction from services.
  • Switched Threat Intelligence sync from Redis to NATS.
  • Added event status checks for rescan.
  • Added support for building custom Kubernetes
  • Improved SBOM Radar service performance.
  • Improved Sysdig integration to avoid duplicate vulnerabilities.
  • Changed KDT scanner mappings to use IDs.
  • Simplified license data handling in container services.
  • Replaced Redis with NATS for Threat Intelligence sync communication.
  • Added new fields to Semgrep SAST vulnerabilities
  • Added CVSS Vector field to optional parameters in issue assignment settings.
  • Added Confirmed field to vulnerability models and synced it to Jira as a label

Bug Fixes:

  • Fixed SonarQube scan failures caused by incorrect project ID handling.
  • Fixed issue where long vulnerability names were not fully visible or editable in the UI.
  • Fixed missing API endpoint filter on the Scan Vulnerability page.
  • Fixed Mend API authentication and updated integration configuration defaults.
  • Fixed Amazon Inspector integration issues.
  • Fixed Fortify suppression and vulnerability visibility issues.