Unwrap new features and enhancements on our platform this August! 🎁
🛠️ Custom fix inside the platform: Currently, Custom fix, our AI-based feature for the generation of guides for vulnerability remediation, is available only in our VS Code extension. However, you will soon have it available from within the Fluid Attacks platform regardless of the code editor or IDE your development team uses.
🔄 Branch or URL update management: When you tried to update a branch or URL corresponding to a repository already under our evaluation, this could mean the alteration and loss of findings reported so far since it was more of a target replacement. Fortunately, you will soon have the option to make updates without deactivating the previous repository and, consequently, without altering the reports obtained, as long as the new root retains the same code base as the previous one.
⚠️ Enhanced vulnerability prioritization: You will soon have the opportunity to define concrete values in the Policies section of the platform for a list of vulnerability prioritization criteria. From this, you will get final values in the "Priority" column for each (type of) vulnerability, which, more tailored to your company's needs and principles than a mere CVSS score, will allow you to determine which security issues should be fixed before others.
🧩 New IDE extension: In the near future, we will add one more IDE plugin to our list of integrations with our platform We are talking about an extension for IntelliJ IDEA, from which you will enjoy the same vulnerability management benefits that we offer for VS Code.
📤 Continuous improvement of EaC: We are currently working on overcoming limitations and making it easier for you to configure and use our .fluidattacks file. This file allows you to exclude reports from our tool's SAST, SCA, and DAST scans with what's commonly known as exceptions as code (EaC).