Releases
v4.2
Reports carrying only new and reopened findings, visible regressions, actionable mitigation advice, quieter dependency results and fix verification on by default.
v4.2 is about what a scan says when it runs again. Reports carry what changed rather than everything already known, regressions are impossible to miss, and mitigation advice is short enough to act on.
| Area | What changed |
|---|---|
| Actionable mitigation | Advisories are short and structured — the fix, why it works, what to test — and carry the corrected code. |
| Advisory in a dialog | Long advice opens from the report table with its code snippet in a code view, instead of stretching the row. Verdict and mitigation now read as buttons. |
| Reports of what changed | A scan reports the findings it raised and the ones it reopened. A finding that was already open and was simply found again is no longer repeated. |
| Visible regressions | A finding that came back after being resolved is marked in Vulnerability Management, and is reported again even when fix verification is what found it. |
| Steadier finding identity | One defect described under two neighbouring vulnerability classes is stored once instead of twice. |
| Quieter dependency results | Component advisories proved unreachable are left out of every report, including the dependency scanner’s own exports. |
| Cheaper dependency rescans | Reachability verdicts are remembered per repository revision, so unchanged code is not verified again. |
| Fix verification by default | A scan that proves a defect is gone now closes the finding without extra configuration, and says plainly when closure is switched off. |
Last reviewed 2026-09-06