Kondukto Release v1.99 3rd February, 2025

Kondukto v1.99 released!

New Features

  • Custom Flags is now available. Flags can now be automatically added to vulnerabilities that meet specific criteria, allowing automation rules to be applied based on these flags. Additionally, these flags can now be pushed as labels to Issue Managers.
  • ASVS column has been added to the Vulnerabilities page.
  • More granular permissions under Automation Setup and Workflow sections can now be granted to custom roles.
  • Custom fields on Azure DevOps Cloud and Server issue manager are now supported.
  • Scan Duration Threshold configuration is now available under Project Settings --> Scanners. With this configuration, when a scan takes longer than this time limit, it will be automatically canceled by Kondukto to prevent hanging scans.
  • OSV Scanner can now be run by providing an SBOM file via KDT.

Improvements

  • Discovered by filter is now available.
  • Plugin and family filters added to Correlation Assistant for enhanced vulnerability correlation and analysis.
  • Projects Issue Assignment page is now divided into two tabs for better performance.
  • Dashboard-Worker Service performance Improved for Infra Dashboards.
  • Scanner Integration page performance has been improved.
  • "Per Page Selection added to Products, Scans Queue, Completed Scans, Failed Scans, and Imports pages for better pagination control.

Bug Fixes

  • The issue preventing Infra Profiles from being searchable on the Scans screen has been fixed.
  • SBOM Inspection now runs immediately upon importing a new SBOM, instead of waiting 12 hours.
  • The bug in Checkmarx where scan parameters were not being created for the correct branch has been fixed.
  • The bug where the Notifier Email Template was broken has been fixed.
  • The bug where the session expired unexpectedly when a user had multiple tabs open has been fixed.
  • The bug in Trivy Operator where vulnerabilities were not being fetched correctly has been fixed.
  • The bug where Nuclei JSON import via KDT was failing has been fixed.
  • The bug where Kondukto was posting duplicate comments on Jira issues has been fixed.
  • The bug where the Checkov scanner was not functioning properly has been fixed.