Rich remediation guidance with risk vs. effort mapping, direct vs. transitive dependencies, container base image vs. layer information, and more.
For additional details on release 3.4, for both on-prem and SaaS versions, please review the Release Notes in Deepfactor Docs.
Release 3.4 Highlights: Enhancements SBOM and SCA for OSS Dependencies and Container Scans Ability to tag scans to a particular release.
Identify vulnerability trends across builds in a particular release and also across releases.
Ability to tag dependencies detected during filesystem scans as transitive and identifying the root dependency for Java.
Detection of Node.js and PHP dev dependencies for filesystem scans.
Global search for artifacts based on multiple criteria such as resource, vulnerability, and OS distribution.
Recommendations pane that highlights the actions needed to fix direct, transitive, and base image layer vulnerabilities.
Users can now use the reachability results to prioritize vulnerabilities in these dependencies.
This is a Security Bloggers Network syndicated blog from Deepfactor authored by Deepfactor.
This Cyber News was published on securityboulevard.com. Publication date: Fri, 22 Dec 2023 04:13:06 +0000