<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>VRM updates</title>
    <link>https://docs.veracode.com/updates</link>
    <description>Veracode VRM updates</description>
    <language>en</language>
    <copyright>Copyright © 2026 Facebook, Inc.</copyright>
    <lastBuildDate>Thu, 08 Oct 2026 00:00:00 GMT</lastBuildDate>
    <item>
            <title><![CDATA[VRM updates]]></title>
            <link>https://docs.veracode.com/updates/r/VRM_updates</link>
            <guid>https://docs.veracode.com/updates/r/VRM_updates</guid>
            <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The updates on this page apply to Veracode Risk Manager (VRM). Subscribe to the VRM updates RSS feed Feed-icon.png.]]></description>
            <content:encoded><![CDATA[<p>The updates on this page apply to <a href="https://docs.veracode.com/r/Veracode_Risk_Manager" target="_blank" rel="noopener noreferrer" class="">Veracode Risk Manager (VRM)</a>. Subscribe to the <a href="https://docs.veracode.com/updates/rss_vrm.xml" target="_blank" rel="noopener noreferrer" class="">VRM updates RSS feed <img decoding="async" loading="lazy" alt="Feed-icon.png" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH6AUKDRQx5jYYZwAAAw5JREFUOI09kUtoXGUcxX//7/vunZvJYxIdTWyTxiQtRttog7RWaelKxdZorC5FUFAiQgk+NkKr1aUbxV3BjW1B8BF8oLu4sgUrta3BUqulJD5oEpMmmXtn7tzv4WLUsznnLA6cwxGAi4eHJ2/p7H7D+TDmCFpEQIEIIIJIS4sSjBEXHHN/Lawc23n86oxcmr7j0W2bbv2ytrJBlt5AR4JOInRbGV2KUUZQkbRYC6LBlGPIFRfP/P64fnn/wOcmzap5dYjKY68SD46hyl3QWCU0lhCjkMggCpCACATrUJGi2QjjJlYymtUzyn2DtO1+iv8QaksUP3+Fu3AS0j+RqBulFSLgCo/NciKjRvX0vr43S5FCjKCMhnwDKVeQcg968zjmzoOQLsLSHCpOcAXYhscXgXrdI/Ovj4f2RAMWcSmKHF2pEt/zBNF9U0h7FQB3+h2K7z/ASQXXDPhmYKPuUChQLiUeupfK9Cztz5wi3n4Qd/4EzROPEBZOA6AfeA1GJrBrq9jc43JP8KBEQJmAShJUdz9meC/xQ2+RPPsN6uYhis+exs9/B0DpwaP4cj82reOageADChFUuYOwOEc+8yL27HFCfRXpGSY6dBJ6d1H/5CXCxiKSdJLsfQFbq+GKAOHfBjqOEFfDX/kaO3sE+9EkYWkOdEx04D3sRko2+z4AyfgE0rUFm+WtBv9PUBDte4X4yQ+RUgfNmSlCuox09WF2PUd6+mN8bQUptRMN78bWUkIAJUoQX0dv3om5/zBq68Oo/cdo/nGZ5tlTAMQ7DmDX1mhePQdANDCGy21rglaCMgYaf0ORti67/gvOJeS//dAK9G/Hm06KpYWW7xvGO0EBMn90/NLAXZXRYm2d0DWCT26jeeUMNsvxqgNz+x58YUl//BbVM4Dp3UZz+Tr62k/Uq+ayXJgambh7z+AXaE99+QY2y3G+DVcobKPArq/jikAwnbisgc3qtLclVLf2ci1dmRSA888PHdq05aYjPjBmi6C9DwQPwbeuCj4QAhBAi7iopOZWsvW3d7z766f/ALd5WtiP5SpGAAAAAElFTkSuQmCC" width="16" height="16" class="img_ev3q"></a>.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="may-26-2026">May 26, 2026<a href="https://docs.veracode.com/updates/r/VRM_updates#may-26-2026" class="hash-link" aria-label="Direct link to May 26, 2026" title="Direct link to May 26, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="automated-workflows">Automated workflows<a href="https://docs.veracode.com/updates/r/VRM_updates#automated-workflows" class="hash-link" aria-label="Direct link to Automated workflows" title="Direct link to Automated workflows" translate="no">​</a></h3>
<p><a href="https://docs.veracode.com/r/using_patterns" target="_blank" rel="noopener noreferrer" class="">Patterns</a> are now available from the VRM settings page, allowing you to automatically:</p>
<ul>
<li class="">Assign assets to applications.</li>
<li class="">Assign labels to assets.</li>
<li class="">Create tickets from issues.</li>
<li class="">Update the status of issues.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="march-26-2026">March 26, 2026<a href="https://docs.veracode.com/updates/r/VRM_updates#march-26-2026" class="hash-link" aria-label="Direct link to March 26, 2026" title="Direct link to March 26, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="table-enhancements">Table enhancements<a href="https://docs.veracode.com/updates/r/VRM_updates#table-enhancements" class="hash-link" aria-label="Direct link to Table enhancements" title="Direct link to Table enhancements" translate="no">​</a></h3>
<p>With improvements to tables in VRM, you can now:</p>
<ul>
<li class="">Export the Applications table with custom filters applied as a CSV file.</li>
<li class="">View IP addresses in the Assets table in a dedicated column.</li>
<li class="">Search by Target Name in the Solutions table.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="adds-details-to-mpt-issues">Adds details to MPT issues<a href="https://docs.veracode.com/updates/r/VRM_updates#adds-details-to-mpt-issues" class="hash-link" aria-label="Direct link to Adds details to MPT issues" title="Direct link to Adds details to MPT issues" translate="no">​</a></h3>
<p>Veracode Manual Penetration Testing (MPT) issue details now include Severity, Exploit, Remediation, and Location fields.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="january-23-2026">January 23, 2026<a href="https://docs.veracode.com/updates/r/VRM_updates#january-23-2026" class="hash-link" aria-label="Direct link to January 23, 2026" title="Direct link to January 23, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="veracode-mpt-results-are-now-available-in-vrm">Veracode MPT results are now available in VRM<a href="https://docs.veracode.com/updates/r/VRM_updates#veracode-mpt-results-are-now-available-in-vrm" class="hash-link" aria-label="Direct link to Veracode MPT results are now available in VRM" title="Direct link to Veracode MPT results are now available in VRM" translate="no">​</a></h3>
<p>Users who have Veracode Manual Penetration Testing (MPT) results can now see individual MPT records as issues in VRM.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="november-27-2025">November 27, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#november-27-2025" class="hash-link" aria-label="Direct link to November 27, 2025" title="Direct link to November 27, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="adds-support-for-qualys-tag-metadata">Adds support for Qualys tag metadata<a href="https://docs.veracode.com/updates/r/VRM_updates#adds-support-for-qualys-tag-metadata" class="hash-link" aria-label="Direct link to Adds support for Qualys tag metadata" title="Direct link to Adds support for Qualys tag metadata" translate="no">​</a></h3>
<p>Qualys tag metadata is now displayed in the detail page for an issue.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="november-12-2025">November 12, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#november-12-2025" class="hash-link" aria-label="Direct link to November 12, 2025" title="Direct link to November 12, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="adds-asset-label-filtering-for-issues">Adds asset label filtering for issues<a href="https://docs.veracode.com/updates/r/VRM_updates#adds-asset-label-filtering-for-issues" class="hash-link" aria-label="Direct link to Adds asset label filtering for issues" title="Direct link to Adds asset label filtering for issues" translate="no">​</a></h3>
<p>You can now filter issues in VRM by the asset labels of assets associated with those issues.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="november-9-2025">November 9, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#november-9-2025" class="hash-link" aria-label="Direct link to November 9, 2025" title="Direct link to November 9, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="integrates-vrm-with-veracode-platform-identity-management">Integrates VRM with Veracode Platform identity management<a href="https://docs.veracode.com/updates/r/VRM_updates#integrates-vrm-with-veracode-platform-identity-management" class="hash-link" aria-label="Direct link to Integrates VRM with Veracode Platform identity management" title="Direct link to Integrates VRM with Veracode Platform identity management" translate="no">​</a></h3>
<p>VRM is now integrated with the Veracode Platform for authentication, user management, and team management.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="october-29-2025">October 29, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#october-29-2025" class="hash-link" aria-label="Direct link to October 29, 2025" title="Direct link to October 29, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="adds-support-for-gcp-onboarding">Adds support for GCP onboarding<a href="https://docs.veracode.com/updates/r/VRM_updates#adds-support-for-gcp-onboarding" class="hash-link" aria-label="Direct link to Adds support for GCP onboarding" title="Direct link to Adds support for GCP onboarding" translate="no">​</a></h3>
<p>VRM now supports GCP onboarding with a new user interface that includes a workflow for mapping GCP tagging to VRM factors.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="october-24-2025">October 24, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#october-24-2025" class="hash-link" aria-label="Direct link to October 24, 2025" title="Direct link to October 24, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="gcp-asset-updates-for-october">GCP asset updates for October<a href="https://docs.veracode.com/updates/r/VRM_updates#gcp-asset-updates-for-october" class="hash-link" aria-label="Direct link to GCP asset updates for October" title="Direct link to GCP asset updates for October" translate="no">​</a></h3>
<p>VRM adds support for assets from the following sources:</p>
<ul>
<li class="">GCP Firestore</li>
<li class="">GCP Secret Manager</li>
<li class="">GCP Certificate Manager</li>
<li class="">GCP KMS key</li>
<li class="">GCP users</li>
<li class="">GCP compute group</li>
<li class="">GCP Networking</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="september-23-2025">September 23, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#september-23-2025" class="hash-link" aria-label="Direct link to September 23, 2025" title="Direct link to September 23, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="gcp-asset-and-findings-updates-for-september">GCP asset and findings updates for September<a href="https://docs.veracode.com/updates/r/VRM_updates#gcp-asset-and-findings-updates-for-september" class="hash-link" aria-label="Direct link to GCP asset and findings updates for September" title="Direct link to GCP asset and findings updates for September" translate="no">​</a></h3>
<p>VRM adds support for assets and findings from the following sources:</p>
<p><strong>Assets:</strong></p>
<ul>
<li class="">GCP Cloud SQL database</li>
<li class="">GCP roles</li>
<li class="">GCP projects</li>
</ul>
<p><strong>Findings:</strong></p>
<ul>
<li class="">GCP Security Command Center</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="september-20-2025">September 20, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#september-20-2025" class="hash-link" aria-label="Direct link to September 20, 2025" title="Direct link to September 20, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="simplified-issue-urls">Simplified issue URLs<a href="https://docs.veracode.com/updates/r/VRM_updates#simplified-issue-urls" class="hash-link" aria-label="Direct link to Simplified issue URLs" title="Direct link to Simplified issue URLs" translate="no">​</a></h3>
<p>Issue URLs in VRM are simplified by removing connector ID information. The unique issue identifier is now sufficient for routing.</p>
<p>Example of the change:</p>
<ul>
<li class=""><strong>Before:</strong> <code>https://app.longbow.security/issues/67a63f200aaa7e13da3a70a8/ae0186ed-d12b-377d-a430-8a036b75e8ce</code></li>
<li class=""><strong>After:</strong> <code>https://app.longbow.security/issues/ae0186ed-d12b-377d-a430-8a036b75e8ce</code></li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="july-19-2025">July 19, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#july-19-2025" class="hash-link" aria-label="Direct link to July 19, 2025" title="Direct link to July 19, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="adds-azure-workstations-to-vrm">Adds Azure workstations to VRM<a href="https://docs.veracode.com/updates/r/VRM_updates#adds-azure-workstations-to-vrm" class="hash-link" aria-label="Direct link to Adds Azure workstations to VRM" title="Direct link to Adds Azure workstations to VRM" translate="no">​</a></h3>
<p>VRM now ingests Azure workstation type assets from the Azure cloud platform. For many users, this includes laptop assets if they are managed by Azure.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="july-17-2025">July 17, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#july-17-2025" class="hash-link" aria-label="Direct link to July 17, 2025" title="Direct link to July 17, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="adds-issue-filtering-by-reason">Adds issue filtering by reason<a href="https://docs.veracode.com/updates/r/VRM_updates#adds-issue-filtering-by-reason" class="hash-link" aria-label="Direct link to Adds issue filtering by reason" title="Direct link to Adds issue filtering by reason" translate="no">​</a></h3>
<p>You can now filter issues in VRM by the reason provided for the status change, such as <code>Remediating Risk</code> or <code>False Positive</code>.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="july-3-2025">July 3, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#july-3-2025" class="hash-link" aria-label="Direct link to July 3, 2025" title="Direct link to July 3, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="displays-qualys-hostname-for-assets">Displays Qualys hostname for assets<a href="https://docs.veracode.com/updates/r/VRM_updates#displays-qualys-hostname-for-assets" class="hash-link" aria-label="Direct link to Displays Qualys hostname for assets" title="Direct link to Displays Qualys hostname for assets" translate="no">​</a></h3>
<p>VRM now shows the hostname instead of the numeric Qualys ID for assets ingested from Qualys.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="may-6-2025">May 6, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#may-6-2025" class="hash-link" aria-label="Direct link to May 6, 2025" title="Direct link to May 6, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="universal-connector-api-for-ingesting-asset-and-finding-data">Universal Connector API for ingesting asset and finding data<a href="https://docs.veracode.com/updates/r/VRM_updates#universal-connector-api-for-ingesting-asset-and-finding-data" class="hash-link" aria-label="Direct link to Universal Connector API for ingesting asset and finding data" title="Direct link to Universal Connector API for ingesting asset and finding data" translate="no">​</a></h3>
<p>The Universal Connector now supports ingesting asset and finding data in CSV or JSON format through an API endpoint.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="may-2-2025">May 2, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#may-2-2025" class="hash-link" aria-label="Direct link to May 2, 2025" title="Direct link to May 2, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="filter-issues-by-veracode-bu-and-teams">Filter issues by Veracode BU and teams<a href="https://docs.veracode.com/updates/r/VRM_updates#filter-issues-by-veracode-bu-and-teams" class="hash-link" aria-label="Direct link to Filter issues by Veracode BU and teams" title="Direct link to Filter issues by Veracode BU and teams" translate="no">​</a></h3>
<p>VRM now ingests business unit and team metadata from Veracode application profiles and allows filtering issues by business unit and team.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="april-10-2025">April 10, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#april-10-2025" class="hash-link" aria-label="Direct link to April 10, 2025" title="Direct link to April 10, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="azure-hybrid-compute-assets">Azure Hybrid Compute assets<a href="https://docs.veracode.com/updates/r/VRM_updates#azure-hybrid-compute-assets" class="hash-link" aria-label="Direct link to Azure Hybrid Compute assets" title="Direct link to Azure Hybrid Compute assets" translate="no">​</a></h3>
<p>VRM now ingests Azure Hybrid Compute assets and associates them with issues identified by Defender or other finding sources.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="march-27-2025">March 27, 2025<a href="https://docs.veracode.com/updates/r/VRM_updates#march-27-2025" class="hash-link" aria-label="Direct link to March 27, 2025" title="Direct link to March 27, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="new-vrm-features">New VRM features<a href="https://docs.veracode.com/updates/r/VRM_updates#new-vrm-features" class="hash-link" aria-label="Direct link to New VRM features" title="Direct link to New VRM features" translate="no">​</a></h3>
<ul>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#new-connectors" class="">New Connectors</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#second-party-package-analysis" class="">Second-Party Package Analysis</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#column-management" class="">Column Management</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#ticketing-metrics" class="">Ticketing Metrics</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#dashboard-charts" class="">Dashboard Charts</a></li>
</ul>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="new-connectors">New connectors<a href="https://docs.veracode.com/updates/r/VRM_updates#new-connectors" class="hash-link" aria-label="Direct link to New connectors" title="Direct link to New connectors" translate="no">​</a></h4>
<p>These new connectors allow Veracode Risk Manager (VRM) to quickly and easily ingest security findings and asset inventory from a variety of popular security tools.</p>
<p><strong>Azure DevOps Ticketing</strong></p>
<p>This ticketing connector enhances the issue management workflow in VRM by allowing users to create tickets in Azure DevOps (ADO) for any issue in VRM. This connector is bidirectional: as tickets are resolved in ADO that status change will be reflected in VRM.</p>
<p><strong>CrowdStrike CWP</strong></p>
<p>CrowdStrike Cloud Workload Protection (CWP) provides runtime protection, threat detection, and visibility for workloads across cloud environments. It helps secure containers, virtual machines, and Kubernetes deployments by identifying and stopping threats in real time.</p>
<p><strong>GitHub Advanced Security</strong></p>
<p>GitHub Advanced Security (GHAS) delivers integrated security capabilities to secure the software development lifecycle directly within GitHub. It includes code scanning for identifying vulnerabilities in code, secret scanning to detect and prevent credential exposure, and dependency review to analyze risks in third-party packages.</p>
<p><strong>JFrog Artifactory</strong></p>
<p>JFrog Artifactory is a universal artifact repository that securely stores, manages, and distributes software packages, binaries, and containers.</p>
<p><strong>Qualys</strong></p>
<p>Qualys is a widely recognized leader in cloud-based vulnerability management, offering comprehensive security solutions to help organizations identify, assess, and remediate potential threats. VRM’s connector ingests vulnerability findings from Qualys for inclusion in VRM’s issue analysis and reporting.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="second-party-package-analysis">Second-party package analysis<a href="https://docs.veracode.com/updates/r/VRM_updates#second-party-package-analysis" class="hash-link" aria-label="Direct link to Second-party package analysis" title="Direct link to Second-party package analysis" translate="no">​</a></h4>
<p>VRM now analyzes Veracode SAST findings to identify Second Party Packages, which are libraries built internally and used across application teams. VRM creates solutions that identify the specific package so development teams can select the highest-impact remediation actions.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="column-management">Column management<a href="https://docs.veracode.com/updates/r/VRM_updates#column-management" class="hash-link" aria-label="Direct link to Column management" title="Direct link to Column management" translate="no">​</a></h4>
<p>In the issue and asset tables, you can customize the displayed columns. This allows you to select from VRM’s extensive contextual data, including numerous Urgency Factors and Severity Factors. These tools enable you to create views that instantly identify outliers and dangerous factor combinations and assess compliance without needing to drill down into the details.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="ticketing-metrics">Ticketing metrics<a href="https://docs.veracode.com/updates/r/VRM_updates#ticketing-metrics" class="hash-link" aria-label="Direct link to Ticketing metrics" title="Direct link to Ticketing metrics" translate="no">​</a></h4>
<p>Application security teams can now track MTTR and MTTA for their Jira, ServiceNow, and ADO tickets created within VRM. Ticket disposition is easily tracked in any VRM table or dashboard.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="dashboard-charts">Dashboard charts<a href="https://docs.veracode.com/updates/r/VRM_updates#dashboard-charts" class="hash-link" aria-label="Direct link to Dashboard charts" title="Direct link to Dashboard charts" translate="no">​</a></h4>
<p>Custom dashboards have two new card types: donut charts and bar charts. These new dashboard card types can be used to graphically represent issues and can be filtered by any dimension available in VRM, including account, tag, application, asset type, compliance framework, and ticket status.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="october-31-2024">October 31, 2024<a href="https://docs.veracode.com/updates/r/VRM_updates#october-31-2024" class="hash-link" aria-label="Direct link to October 31, 2024" title="Direct link to October 31, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="new-vrm-features-1">New VRM features<a href="https://docs.veracode.com/updates/r/VRM_updates#new-vrm-features-1" class="hash-link" aria-label="Direct link to New VRM features" title="Direct link to New VRM features" translate="no">​</a></h3>
<ul>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#custom-risk-remediation-dashboards" class="">Custom Risk Remediation Dashboards</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#okta-sso-integration" class="">Okta SSO Integration</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#servicenow-connector" class="">ServiceNow Connector</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#veracode-connector-15" class="">Veracode Connector 1.5 </a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#vulnerability-management-connectors-rapid7-and-tenable" class="">Vulnerability Management Connectors: Rapid7 and Tenable</a></li>
</ul>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="custom-risk-remediation-dashboards">Custom risk remediation dashboards<a href="https://docs.veracode.com/updates/r/VRM_updates#custom-risk-remediation-dashboards" class="hash-link" aria-label="Direct link to Custom risk remediation dashboards" title="Direct link to Custom risk remediation dashboards" translate="no">​</a></h4>
<p>With VRM custom dashboards, administrators can easily customize how you visualize your application security, risk reduction, or issue prioritization. You can create dashboards that meet the specific needs of your organization.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="okta-sso-integration">Okta SSO Integration<a href="https://docs.veracode.com/updates/r/VRM_updates#okta-sso-integration" class="hash-link" aria-label="Direct link to Okta SSO Integration" title="Direct link to Okta SSO Integration" translate="no">​</a></h4>
<p>You can now easily manage users via SSO using VRM's Okta integration. Enabling SSO for users allows you to manage authentication compliance through a central system rather than ensuring VRM's sign-on is also compliant, reducing the organizational overhead needed to manage another system's authentication.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="servicenow-connector">ServiceNow Connector<a href="https://docs.veracode.com/updates/r/VRM_updates#servicenow-connector" class="hash-link" aria-label="Direct link to ServiceNow Connector" title="Direct link to ServiceNow Connector" translate="no">​</a></h4>
<p>The ServiceNow Connector for VRM connects VRM's best next actions and issues to ServiceNow's IT Service Management (ITSM) plugin. The connector leverages the ServiceNow API to create incident or request tickets to ensure VRM's powerful recommendations get to the next stage of remediation and are delivered to the correct teams' workflows.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="veracode-connector-15">Veracode Connector 1.5<a href="https://docs.veracode.com/updates/r/VRM_updates#veracode-connector-15" class="hash-link" aria-label="Direct link to Veracode Connector 1.5" title="Direct link to Veracode Connector 1.5" translate="no">​</a></h4>
<p>VRM ingests and analyzes all your Veracode AST findings to create a complete and unified view across Veracode Static Analysis, Dynamic Analysis, and SCA issues. VRM leverages the Veracode Platform's policy enforcement and vulnerable methods data for issue urgency analysis.</p>
<p>In this release, you can also map Veracode issues back to the source code repository where the issues originated. These changes provide rich remediation instructions for weaknesses and vulnerabilities detected by Veracode AST products.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="vulnerability-management-connectors-rapid7-and-tenable">Vulnerability Management Connectors: Rapid7 and Tenable<a href="https://docs.veracode.com/updates/r/VRM_updates#vulnerability-management-connectors-rapid7-and-tenable" class="hash-link" aria-label="Direct link to Vulnerability Management Connectors: Rapid7 and Tenable" title="Direct link to Vulnerability Management Connectors: Rapid7 and Tenable" translate="no">​</a></h4>
<p>The new Rapid7 and Tenable connectors for VRM allow you to bring in critical operational vulnerability data from the assets you are scanning.  Coordinating this data with other risk elements allows your teams to save significant expert time and create tasks that make the most of your resource investments.</p>
<h2 class="anchor anchorTargetStickyNavbar_zFqj" id="august-16-2024">August 16, 2024<a href="https://docs.veracode.com/updates/r/VRM_updates#august-16-2024" class="hash-link" aria-label="Direct link to August 16, 2024" title="Direct link to August 16, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="new-vrm-features-2">New VRM features<a href="https://docs.veracode.com/updates/r/VRM_updates#new-vrm-features-2" class="hash-link" aria-label="Direct link to New VRM features" title="Direct link to New VRM features" translate="no">​</a></h3>
<ul>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#application-security-heatmap" class="">Application Risk Heatmap </a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#universal-connector-10" class="">Universal Connector 1.0</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#gitlab-repository-connector" class="">GitLab Repository Connector: Repository scanning</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#gitlab-ultimate-security-findings-container--sast" class="">GitLab Ultimate Security Findings: Container &amp; SAST</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#veracode-connector-new-asset-type-for-application-profiles" class="">Veracode Connector: New asset type for application profiles</a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#ui-enhancement-saved-filters" class="">UI Enhancement: Saved filters </a></li>
<li class=""><a href="https://docs.veracode.com/updates/r/VRM_updates#early-release-custom-compliance-mappings" class="">Early release: Custom compliance mappings</a></li>
</ul>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="application-security-heatmap">Application security heatmap<a href="https://docs.veracode.com/updates/r/VRM_updates#application-security-heatmap" class="hash-link" aria-label="Direct link to Application security heatmap" title="Direct link to Application security heatmap" translate="no">​</a></h4>
<p>With VRM Applications, you can organize assets into groups that align with your organization’s internal applications. These applications can reflect the work of internal development teams or simply be logical collections of runtime assets that deliver a business function for the enterprise. The application security heatmap provides you with an at-a-glance view of risk for all applications and allows you to drill down and see the assets, issues, solutions, and score trending for a specific application.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="universal-connector-10">Universal Connector 1.0<a href="https://docs.veracode.com/updates/r/VRM_updates#universal-connector-10" class="hash-link" aria-label="Direct link to Universal Connector 1.0" title="Direct link to Universal Connector 1.0" translate="no">​</a></h4>
<p>The VRM Universal Connector enables you to connect to any data source to ingest assets and findings.  It unlocks the potential for VRM to provide its issue prioritization and enrichment to any data source, whether it be a vulnerability scanner, asset discovery tool, CNAPP solution, or cloud security utility, through a straightforward API setup.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="gitlab-repository-connector">GitLab Repository Connector<a href="https://docs.veracode.com/updates/r/VRM_updates#gitlab-repository-connector" class="hash-link" aria-label="Direct link to GitLab Repository Connector" title="Direct link to GitLab Repository Connector" translate="no">​</a></h4>
<p>VRM has added support for the GitLab Repository Connector. This allows VRM to connect to your GitLab repositories, scan the files and logs, and then analyze that data to identify IaC configuration files and inventory image hashes. VRM uses this data to map runtime ACR and ECR images to their origin in the version control system.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="gitlab-ultimate-security-findings-container--sast">GitLab Ultimate security findings: Container &amp; SAST<a href="https://docs.veracode.com/updates/r/VRM_updates#gitlab-ultimate-security-findings-container--sast" class="hash-link" aria-label="Direct link to GitLab Ultimate security findings: Container &amp; SAST" title="Direct link to GitLab Ultimate security findings: Container &amp; SAST" translate="no">​</a></h4>
<p>VRM has added support for the GitLab Ultimate Connector. This connector allows VRM to create issues from Container and SAST findings discovered by GitLab Ultimate. This capability requires no additional setup. If you have already configured the GitLab Repository Connector and you have a license to GitLab Ultimate, VRM will gather these findings automatically.</p>
<h4 class="anchor anchorTargetStickyNavbar_zFqj" id="veracode-connector-new-asset-type-for-application-profiles">Veracode connector: New asset type for application profiles<a href="https://docs.veracode.com/updates/r/VRM_updates#veracode-connector-new-asset-type-for-application-profiles" class="hash-link" aria-label="Direct link to Veracode connector: New asset type for application profiles" title="Direct link to Veracode connector: New asset type for application profiles" translate="no">​</a></h4>
<p>With the Veracode Connector, you can now create assets based on Veracode application profiles.  VRM can display all SAST, DAST, and SCA issues in association with their parent application profile in the Asset and Issue tables in the VRM console. VRM admins can also group these application profile assets within any VRM application (VRM’s native asset grouping).</p>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="ui-enhancement-saved-filters">UI enhancement: Saved filters<a href="https://docs.veracode.com/updates/r/VRM_updates#ui-enhancement-saved-filters" class="hash-link" aria-label="Direct link to UI enhancement: Saved filters" title="Direct link to UI enhancement: Saved filters" translate="no">​</a></h3>
<p>You can now save filters with all the filter menus in the VRM console. You can easily save any combination of filters set for tables or dashboards without needing to leave the filter menus. This allows customers to easily save critical use cases and easily access them across the product.</p>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="early-release-custom-compliance-mappings">Early release: Custom compliance mappings<a href="https://docs.veracode.com/updates/r/VRM_updates#early-release-custom-compliance-mappings" class="hash-link" aria-label="Direct link to Early release: Custom compliance mappings" title="Direct link to Early release: Custom compliance mappings" translate="no">​</a></h3>
<p>The VRM platform now allows you to filter the Issues table by custom compliance standards that you define. This feature is in early release. To enable it, please reach out to your Customer Success Manager.</p>
<p>In addition to any custom compliance mappings your organization implements, VRM supports the following compliance frameworks out-of-the-box: CIS AWS 1.4, CIS AWS 1.5, CIS AWS 2.0, NIST 800-53 Rev 5</p>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="additional-updates">Additional updates<a href="https://docs.veracode.com/updates/r/VRM_updates#additional-updates" class="hash-link" aria-label="Direct link to Additional updates" title="Direct link to Additional updates" translate="no">​</a></h3>
<ul>
<li class="">Updated the API to allow editing of multiple applications in one API request</li>
<li class="">Added support for filters when editing applications with the API</li>
<li class="">Added hash-based vulnerability findings detection to enable collection of additional vulnerabilities from Azure</li>
<li class="">Added “group by” support for specific fields when listing solutions with the API.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_zFqj" id="bug-fixes">Bug fixes<a href="https://docs.veracode.com/updates/r/VRM_updates#bug-fixes" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes" translate="no">​</a></h3>
<ul>
<li class="">Fixed issue where some CVE issues would not be created for application profile assets.</li>
<li class="">Fixed issue where some Prisma Cloud finding types would not generate solutions.</li>
<li class="">Fixed issue with the application histogram where issues with scores at division boundaries were not grouped properly.</li>
</ul>]]></content:encoded>
        </item>
  </channel>
</rss>