What's New¶
Beta release highlights¶
- Deterministic source scanning backed by packaged OpenGrep rules.
- Crypto-function discovery with direct, propagated, and targeted intrafile parameter evidence.
- Quantum-risk, CWE, anti-pattern, numeric policy, and FIPS 140-3 evidence when the required facts are available.
- Lifecycle-aware operation groups for related crypto API calls.
- Portable JSON, CBOM, and SARIF outputs.
- CLI, VS Code, Eclipse, hardened Linux container, and standalone Report Viewer distributions.
- Offline signed trial activation shared by every scanning interface.
- Local report history and comparison workflows in the IDE integrations.
Licensing in this beta¶
The current trial is valid for 15 days and is constrained by the signed entitlement and the beta availability window of 21 August 2026 through 30 September 2026 UTC. The default trial limit is 20 unique repositories and 1,000 eligible source files per repository. The signed license supplied to your organization is authoritative for its effective dates and limits.
Current capability boundaries¶
- Java, C, C#, Go, and Python have broad rule inventories.
- JavaScript has API detection with known metadata gaps.
- C++ and TypeScript currently provide targeted parameter-flow helpers and do not independently provide complete crypto-function inventories.
- Parameter resolution is deterministic and primarily intrafile. Runtime-only, cross-module, environment, request, database, and secret-store values can remain unresolved.
- FIPS results describe scanner evidence and do not certify an application or deployment.
- Transformation Hub functionality is not part of this release.
- Deterministic reports do not require AI. The distributed container keeps AI disabled.
Before upgrading¶
Retain the complete report folder for scans you need to compare or audit. Read the release package notices and use the prerequisite checker delivered with the new version before replacing an existing installation.
See Product Artifacts for deliverable names and intended use.