Release Notes

Introduction

Software supply chain attacks are on the rise and have become a critical concern for all organizations. The modern software delivery pipelines have become increasingly complex, and the threat landscape is continuously evolving. Therefore, a unified and proactive approach to security, risk management, and governance across the software delivery lifecycle is essential.

OpsMx Delivery Shield is a solution that focuses on monitoring, alerting, preventing, and resolving security threats and vulnerabilities across the software delivery lifecycle. It seamlessly integrates with your DevOps ecosystem to gather and evaluate information against a set of secure software delivery practices and frameworks. This ensures that insecure application versions do not get released. The solution also keeps track of all actions, people, and process metadata related to software development, thereby enabling enterprises to meet their compliance requirements with ease.

Version 2024.10.0

Features:

  • Global Exception Creation Feature - A new feature has been introduced in the Alert Summary popup, enabling the creation of global exceptions. Users with admin permissions can now create global-level exceptions. Once created, these exceptions will be logged and displayed on the Audit page for tracking and review.

  • Enhanced CI/CD Workflows: Multi-Artifact Discovery Support - The Jenkins plugin for SSD now supports sending build and deployment events for multiple image artifacts and binary artifacts in a single job, expanding CI/CD workflow capabilities.

    Key Enhancements:

    • Multiple image artifact support.

    • Binary artifact support for non-image artifacts.

  • Expanded Registry Support: Scan Docker Images on GCR & ACR - This release adds support for:

    - Google Container Registry (GCR): Identify vulnerabilities in Docker images

    - Azure Container Registry (ACR): Detects security risks in container images.

  • Open Source Risk Management Analysis - A new feature is added that focuses on helping the customer evaluate the risk status of the various open-source components within their software projects. Detailed insights and assessments of the findings are displayed on the OSS Risk page for better visibility and management.

  • Jenkins Plugins Risk Assessment through the Enabled Plugins - A new feature is added to identify all plugins installed on a customer's Jenkins system and assess their risk levels based on detailed vulnerability profiles.

    Key Enhancements:

    • Actionable policies will be created based on the derived data.

    • The data will be incorporated into the build section of the DBOM for comprehensive risk representation.

Enhancements:

  • Optimised Policies Update Workflow page for improved performance and responsiveness.

Enhancements:

The following issues are fixed in this release:

  • Integration passwords and tokens are now properly encrypted when saved.

  • Role-Based Access Control (RBAC) now correctly handles team selection changes.

  • Smart search hierarchy is introduced in the ‘Vulnerability’ feature.

  • Inconsistencies in the data displayed across different views within the product.

  • Optimization of the performance of the Stage Graph API in the artifact page by replacing individual deployment queries for each artifact with a bulk query to retrieve stages for all artifacts simultaneously.

  • License data is not displayed in the SBOM popup; however, the licenses are visible in the downloaded SBOM file.

  • Context Graph links on the Demo Server are broken, impacting navigation.

Version 2024.9.0

Features:

  • OWASP ZAP DAST Tool Integration - Delivery Shield now supports OWASP ZAP DAST tool, thus enhancing the ability to assess the security posture of applications in their operational state by actively testing it for vulnerabilities. By evaluating applications in real time, the DAST tool provides security assurance by identifying potential vulnerabilities that might otherwise go unnoticed.

Enhancements:

  • Performance improvements have been implemented across various pages including Security Issues, Vulnerabilities and Artifact Security as listed below:

    • Alerts Graphs in Security Issue Page

    • Alerts Page Smart Search

    • Alerts Page Listing

    • Vulnerability Page Smart Search

    • Vulnerability Page Listing

    • Policies Update Workflow

    • Exceptions add-on to alerts

    • Exceptions add-on to vulnerabilities

    • Most Frequent Security Issues

    • Artifact Security Page Listing

    • Trivy Image scans

Version 2024.8.0

Features:

  • Application Versions Tracking - Delivery Shield now allows tracking of application versions. Users can tag artifacts with application and version information, enabling application stack visibility in the dashboard. It also supports continuous scanning and uniform artifact presentation.

  • Delta Cloning - Delivery Shield enables efficient processing of large monorepos by cloning only the changed files thus improving the performance and reducing operational issues.

  • Support for K8s and Non-K8s Deployments on the same instance - Delivery Shield now supports managing both Kubernetes and non-Kubernetes deployments within a single SSD instance. This feature simplifies deployment management and enhances flexibility.

  • Importing CVE Suppression List - Delivery Shield enables users to import lists of suppressed CVEs or non-fixable CVEs and also supports CSV file uploads and UI filtering.

  • Jira Plugin Automation - To track the high-priority security issues found through Delivery Shield, Jira tickets can be created. With this release, one can automate the Jira creation relieving the user from manual task. With this automation with Jira, the security incident management is streamlined.

  • Exception Workflows and Approval Process - Delivery Shield has now introduced a workflow for processing security exceptions. The approval processes are enabled and the security incident management is enhanced.

Enhancements:

  • CVE Prioritization - The CVE prioritization column is enhanced to display the correct severity of the vulnerabilities.

  • Vulnerability Prioritization Graph - The Y-axis in the Vulnerability Prioritization graph is changed to Priority instead of EPSS to improve the visualization of the priority information.

  • OSV and NVD - The Vulnerability Report is enhanced to cover data from multiple vulnerability databases such as Integrated Open Source Vulnerability (OSV), National Vulnerability Database (NVD) and GHSA (GitHub Security Advisory) to improve the performance of the generated reports.

  • Alert Popup - The alert popup is enhanced to include relevant metadata to make it more actionable.

  • Jenkins Plugin - Token-based authentication is implemented in Jenkins plugin to enhance security for API access.

Version 2024.7.0

Features:

  • Bitbucket Pipelines Integration - Delivery Shield now supports Bitbucket Pipelines as a CI tool. It can receive build events from Bitbucket Pipelines, performing security scans on both the build pipeline and the artifacts produced.

  • Codacy Integration - Delivery Shield integrates with Codacy to gather source code scan results. These results are evaluated against secure software delivery policies and are factored into the application’s overall security score.

Enhancements:

  • Jenkins Plugin Enhancements - The Delivery Shield Jenkins plugin now supports Jenkins jobs that produce JAR and WAR files. It can detect, scan, and continuously monitor these files built by Jenkins.

  • License and Vulnerability data in SBOM - The Software Bill of Materials (SBOM) generated by Delivery Shield now includes license and vulnerability data for each component, enhancing transparency and security insights.

  • POST API Mode for SonarQube - SonarQube scan results can now be posted to Delivery Shield via an API, in addition to the previous fetch-based mechanism for greater efficiency.

Version 2024.6.0

Features:

  • License Scanning - Delivery Shield now scans your code repositories and build artifacts (including images and packages) to detect third-party libraries and their associated licenses. It identifies the use of restricted license categories and flags them as security issues.

  • Sneak SAST Integration - Delivery Shield integrates with Snyk SAST to collect source code scan results. These results are evaluated against secure software delivery policies and are factored into the overall application security score.

  • Virus Total Integration - Delivery Shield detects URLs in your codebase and build pipelines, using VirusTotal to flag any malicious URLs.

  • ECR Integration - Delivery Shield now supports Amazon ECR as an artifact storage solution. It can fetch artifacts from ECR and perform security scans on them.

Enhancements:

  • AI-powered Remediation Enhancements - The AI-powered remediation now includes the ability to generate recommendations for upgrading insecure dependencies and suggest alternatives to vulnerable libraries.

  • Scanning Status - A new status, Scanning is introduced across multiple pages to clearly indicate when a security scan is in progress.

  • DBOM enhancements - The Delivery Bill of Materials (DBOM) is streamlined by reducing the number of subcategories under each stage, making it easier to navigate and manage.

Version 2024.5.0

Features:

  • Vulnerability Prioritisation - Delivery Shield now can prioritize vulnerabilities using an algorithm that takes into account parameters such as exploitability, severity, and KEV Database.

  • Deduplication - Delivery Shield now can deduplicate vulnerabilities and security issues, allowing security teams to better focus on resolving these issues. In the alert detail popup, a new section called "Show Impacted Components" has been added. This section enables users to view the complete list of Accounts, Applications, Artifacts, and Services affected by a vulnerability.

  • Artifact Security - The new artifact security feature displays a list of all artifacts auto-discovered by Delivery Shield, along with their security status. It also allows viewing the lifecycle of these artifacts and downloading security scan results related to them.

  • JIRA Integration - User can create a JIRA ticket directly from the alert details screen, which will include all relevant information for developers to track and resolve the issue.

  • GitHub Actions Integration - Delivery Shield now supports GitHub Actions as a CI tool. It can receive build events from GitHub Actions to run security analysis of the build pipeline as well as the produced images.

  • Cluster Management - The new Clusters page enables users to connect their Kubernetes clusters to Delivery Shield, allowing Delivery Shield to continually monitor the security posture of the connected clusters and send alerts when necessary.

Enhancements:

  • The App level policies are now listed based on the tools used in that application context. Users have to deal with only the policies required by the selected application.

Bug Fixes

  • The policy page performance issues have been resolved.

Version 2024.4.0

Features:

  • Vulnerability scanning for Debian packages - Delivery Shield can now detect vulnerabilities in Debian packages.

  • Support for the Spinnaker Bake Stage - Delivery Shield can process events emitted by the Spinnaker image bake stage to analyze the composition of a machine image.

  • Support for Machine Image Deployments - Delivery Shield now detects and performs scans on machine image-based deployments executed via Spinnaker, providing support for machine image deployments.

  • Agentless Kubernetes Scans - kube-detector is the Delivery Shield component used to scan Kubernetes clusters. It can now perform scans without running an agent in the cluster.

  • BitBucket Integration - The new Bitbucket integration enables Delivery Shield to retrieve metadata about the source code repository and perform security scans to produce reports such as the OpenSSF Scorecard.

Enhancements:

  • Support for running multiple kube-detector instances along with Delivery Shield is now available, allowing them to point to different Kubernetes clusters.

  • NamespacesToAllow and NamespacesToIgnore fields in the kube-detector configuration allow users to specify the set of namespaces to watch and ignore, respectively.

Bug Fixes

  • Minor bug fixes.

Version 2024.3.0

Features:

  • Organization Structure and RBAC - A new three-tier organizational structure is introduced in this release that enables customers to manage their applications across various business units and teams using a single Delivery Shield instance. Additionally, it offers an enhanced Role-Based Access Control system for better control over the user permissions.

  • Kubernetes Discovery - Deploy Shield detects changes in a Kubernetes cluster and enforces security policies through agent-based resource discovery.

Enhancements:

  • UX enhancements.

  • Minor bug fixes.

Version 2024.2.0

Features

  • Non-Blocking mode - Delivery Shield can be used in a non-blocking mode by disabling the deployment firewall feature, that is best suited for lower environments like Development and QA. This mode doesn't block deployments but evaluates policies and generates security alerts.

  • New integrations

    • Integration with Gitlab to collect source code metadata, Git security posture checks, and generate an OpenSSF Scorecard.

    • Integration with Jfrog Artifactory to fetch images and run security scans.

    • Integration with Snyk to run Security scans and fetch reports.

  • Support for Non-Kubernetes deployments - It is now possible to conduct security scans on Amazon ECS deployments using Delivery Shield.

  • UI For managing Delivery Shield Integrations - A new page named Integrations is added to the Config menu. This page enables users to integrate and manage Delivery Shield with their preferred DevOps tools.

Enhancements

  • Enhanced Navigation Experience - The navigation structure is revamped and new menu items are added, to support additional use cases and personas.

Version 2023.11.0

Features

  • Policy as Code and GitOps - Users can transform security policies into code, store them in a Git repository, and periodically synchronize them with Delivery Shield.

  • Helm Charts Security - Delivery Shield has introduced support for Helm chart scanning. This feature enables the identification of misconfigurations and security issues within the Helm charts.

Enhancements

  • Improved workflow for Integrating Jenkins with Delivery Shield.

  • Users can now perform bulk actions on the Rules Configuration page by selecting multiple rules and modifying them simultaneously.

  • The Delivery Bill of Materials (DBOM) page has been improved with better labelling and grouping of information.

Version 2023.10.0

Features

  • Kubernetes Hardening Analysis

    • CIS Benchmark analysis for Kubernetes clusters - Delivery Shield automatically evaluates connected clusters for CIS Benchmark compliance using 200+ predefined deployment firewall rules. Kubernetes posture-related alerts and suggestions are available on the Manage Alerts Page.

    • Additionally, it allows for the assessment of your clusters according to the guidelines provided by NSA-CISA and MITRE ATT&CK.

  • Jenkins Integration - Delivery Shield now supports Jenkins as a build and deployment tool, gathering information to improve security posture through alerts and recommendations.

  • Deployment History Timeline - The application status page now displays cluster deployments as a timeline graph, providing an audit trail and historical view of changes to cluster security posture.

  • Vulnerability Report - The application status page now displays vulnerability reports for both the application and service.

Enhancements

  • Added support for user-defined tags for deployment firewall rules, allowing users to group rules based on the custom logic.

  • Expanded the functionality of the smart search feature to include the alerts and vulnerabilities report page.

  • Added the ability to distinguish between alerts on the current and the old versions of running applications.

Version 2023.9.0

Features

  • Deployment Firewall - The Kubernetes cluster can now automatically block insecure application versions from being deployed by running an admission control mechanism. This decision-making is powered by Delivery Shield's security analysis and data collection throughout the software delivery lifecycle.

  • New SAST Integrations - Delivery Shield can now mandate SAST scans during software development, analyze reports to provide suggestions, and update the application's risk status by connecting to SonarQube and Semgrep.

  • Smart Search - The ability to discover vulnerabilities, images, and other components across all applications allows for easier identification of newly found vulnerabilities within existing applications.

  • OpenSSF Scorecard Integration - Connected git repositories will receive an OpenSSF scorecard with security posture alerts and suggestions accessible on the Manage Alerts Page.

  • NIST and FedRAMP Compliance Automation - Delivery Shield now includes prebuilt policies for NIST 800-53 and FedRAMP compliance, with suggestions for fixing issues and achieving 100% compliance.

  • Rules Genie - A new AI assistant that creates custom deployment firewall rules based on business requirements.

  • Alerts Genie - A new AI assistant that helps understand security alerts and recommends solutions.

Enhancements

  • Application level Smart Diff and Application DBOM - Users can now perform Smart Diff at the application level and view the Delivery bill of materials for the entire application version.

  • Search and filtering options - In the Alerts Management and Rules Configuration pages, you can access additional search and filtering options.

Version 2023.8.0

Features

  • Ability to collect software delivery data from Git, Jenkins, Spinnaker, Kubernetes, and Aqua Trivy.

  • Supply chain dashboard - Helps you to view the organization-level security posture, applications and their risk status and security alerts.

  • Application status page - Displays the security status, active vulnerabilities, and alerts of the running services.

  • Alerts Management - Ability to track and resolve security alerts across environments with Delivery Shield suggestions.

  • SBOM - Generate software bill of materials for the deployed images.

  • DBOM - The Delivery Bill of Actions and Materials is a comprehensive report that offers complete visibility of the software development process, from coding to deployment. It keeps track of crucial information such as tools used, actions taken, artifacts produced, and security checks performed during the software delivery process. This report serves as a valuable tool to monitor and optimize software development.

  • Smart Diff - Helps you to dry run code promotion from one environment to another. By doing so, you can compare the services that run in different environments in terms of their security status, active alerts, vulnerabilities, and dependencies. This helps you understand the impact that a new version of a service may have when deployed to production.

  • Slack Integration - Ability to share alerts to Slack channels.

Last updated