Releases

v4.2

Reports carrying only new and reopened findings, visible regressions, actionable mitigation advice, quieter dependency results and fix verification on by default.

v4.2 is about what a scan says when it runs again. Reports carry what changed rather than everything already known, regressions are impossible to miss, and mitigation advice is short enough to act on.

AreaWhat changed
Actionable mitigationAdvisories are short and structured — the fix, why it works, what to test — and carry the corrected code.
Advisory in a dialogLong advice opens from the report table with its code snippet in a code view, instead of stretching the row. Verdict and mitigation now read as buttons.
Reports of what changedA scan reports the findings it raised and the ones it reopened. A finding that was already open and was simply found again is no longer repeated.
Visible regressionsA finding that came back after being resolved is marked in Vulnerability Management, and is reported again even when fix verification is what found it.
Steadier finding identityOne defect described under two neighbouring vulnerability classes is stored once instead of twice.
Quieter dependency resultsComponent advisories proved unreachable are left out of every report, including the dependency scanner’s own exports.
Cheaper dependency rescansReachability verdicts are remembered per repository revision, so unchanged code is not verified again.
Fix verification by defaultA scan that proves a defect is gone now closes the finding without extra configuration, and says plainly when closure is switched off.

See Rescans and fix verification and Reports and exports.

Last reviewed 2026-09-06