Skip to content

Commit

Permalink
release notes for pascal 3
Browse files Browse the repository at this point in the history
  • Loading branch information
Kamesh-PaloAlto committed Jan 6, 2025
1 parent f2b17b5 commit 1b2d519
Showing 3 changed files with 138 additions and 88 deletions.
10 changes: 10 additions & 0 deletions docs/en/enterprise-edition/rn/known-issues/known-fixed-issues.adoc
Original file line number Diff line number Diff line change
@@ -76,6 +76,16 @@ Custom roles cannot be configured to include these permissions, as Google Cloud

If the Viewer role or domain related built in role is not configured, the API ingestion will fail, and `'Missing Permissions'` warning for the above permissions will not be displayed on the account status page.

|*CWP-59515*

|The K8s defender pods on the RKE2 go into a crash loop if the defender is deployed using the default YAML file options.

*Workaround*: For Kubernetes defenders on RKE2, create the YAML file with the “SELinux Policy” option. Note that the workaround is applicable to RKE2 only.

|*CWP-62358*

|When a Go binary has no listed dependencies in its build information (verified using `go version -m <path to binary>`), the version of its external dependencies is used to identify the version of the Go binary. This could result in incorrect vulnerability data.


|*RLP-146718*
//Added on 8/14/2024 after 24.8.1
Original file line number Diff line number Diff line change
@@ -1,18 +1,17 @@
== Look Ahead—Planned Updates to Secure the Runtime

//Currently, there are no previews or announcements for updates.
Currently, there are no previews or announcements for updates.

The following sections provide a preview of the planned updates for the `v33.03` release of Runtime Security.
//The following sections provide a preview of the planned updates for the `v33.03` release of Runtime Security.

*NOTE*:
//*NOTE*:

The details and functionality listed below provide a preview of what is planned for the `v33.03` release. Both the updates and their actual release dates are subject to potential changes.
//The details and functionality listed below provide a preview of what is planned for the `v33.03` release. Both the updates and their actual release dates are subject to potential changes.


//*<<announcement>>
//*<<intelligence-stream-updates>>
//*<<enhancements>>

//* <<changes-in-existing-behavior>>
//* <<new-policies>>
//* <<policy-updates>>
@@ -21,48 +20,4 @@ The details and functionality listed below provide a preview of what is planned
//* <<api-ingestions>>
//* <<deprecation-notices>>

=== Intelligence Stream Updates

==== Enhancements to Vulnerability Reporting for Red Hat Enterprise Linux (RHEL) Versions 8 and 9
//CWP-30827
To ensure accurate vulnerability reporting, Intelligence Stream will include RPM module and stream information for RHEL. This approach improves detection of vulnerabilities and ensures that all associated RPM packages installed by a module are examined during the scan.

*What are RPM Modules and Streams?*

In Red Hat Enterprise Linux (RHEL), an RPM module is a collection of related RPM packages that represent a software component, such as an application, its dependencies, and helper utilities. Starting with RHEL 6 and 7, modules replaced the Software Collections mechanism.

Modules are structured in the following way:

* *Module Streams*: Virtual repositories within the AppStream repository. Each stream corresponds to a specific version of the module and receives independent updates.

* *Stream Activation*: At any time, only one stream of a module can be active, meaning only one version of a component can be installed on a system.

For example, the notation `python39:3.9/python39` indicates the module `python39`, the stream `3.9`, and the source package `python39`.

*Enhancements to Vulnerability Reporting*

* *Module-Based Vulnerability Identification*: Scans will report vulnerabilities based on the module and stream configuration. This ensures accurate detection and avoids false positives or false negatives caused by discrepancies in versioning or backported fixes.

* *Inclusion of RPM Module Metadata in Scan Results*: The enhanced implementation associates RPM packages with their respective modules and streams. The Prisma Cloud console will include this module information in vulnerability scan results.


*Benefits of Module-Aware Vulnerability Reporting*

* *Improved Accuracy*: Matches CVE fixes to the correct module stream.
* *Reduced False Positives*: Avoids misreporting of vulnerabilities fixed in older streams.
* *Comprehensive Coverage*: Links all RPM packages installed by a module to its vulnerabilities.

==== Enhanced Vulnerability Reporting for NuGet Packages
//CWP-49786
Previously, the scanning process included NuGet packages listed in the `.deps.json` files, which were essential for the runtime environment but not related to the application itself. These unrelated packages result in false positives in vulnerability reporting.

With this enhancement, the scanning process excludes runtime-specific dependencies that are not directly related to the application. This provides a more accurate view of vulnerabilities directly associated with the application, and reduces false positive alerts.


*NOTE*:

* This enhancement requires upgrading Defenders to the latest version.

* The updated Defender accurately identifies package dependencies, which leads to fewer false positives.

* Older Defender versions will remain unaffected by this change, and their behavior remains unchanged.
Original file line number Diff line number Diff line change
@@ -1,69 +1,154 @@
== Features Introduced in January 2024

Learn what's new on Prisma® Cloud in January 2024.

* <<announcement>>
* <<new-features>>
* <<api-ingestions>>
* <<new-policies>>
* <<policy-updates>>
* <<policy-updates-iam>>
* <<new-compliance-benchmarks-and-updates>>
* <<rest-api-updates>>
Learn what's new on Prisma® Cloud in January 2025.

* <<enhancements>>
* <<intelligence-stream-updates>>
//* <<announcement>>
//* <<new-features>>
//* <<api-ingestions>>
//* <<new-policies>>
//* <<policy-updates>>
//* <<policy-updates-iam>>
//* <<new-compliance-benchmarks-and-updates>>
//* <<rest-api-updates>>
//* <<changes-in-existing-behavior>>
* <<deprecation-notices>>
//* <<deprecation-notices>>
[#announcement]
=== Announcement
//[#announcement]
//=== Announcement

[cols="50%a,50%a"]
//[cols="50%a,50%a"]
//|===
//|*Feature*
//|*Description*
//|===

[#enhancements]
=== Enhancements
[cols="30%a,70%a"]
|===
|*Feature*
|*Description*

|Enhancement to Prevent Action with `fsmon_v2`
//CWP-62711

|To improve the handling of file system events for Prevent Action in the Runtime Policy, `fsmon_v2` has been developed. This new version of fsmon manages event timeouts in an efficient way. This enhancement ensures independent handling of each event, reduces bottlenecks, and improves overall performance.

|===
NOTE: While `fsmon_v2` brings significant improvements, it is still under active development, and further stability enhancements are planned.

By default, fsmon_v2 is not enabled. To activate it, set the environment variable `FSMON_V2=true`.

You can verify the configuration by checking the Defender logs for the message, `Initializing filesystem monitoring agent /usr/local/bin/fsmon_v2`.

[#new-features]
=== New Features

[cols="50%a,50%a"]
|"last-connected" Field Added to Defender Stats Logs
//CWP-62666

tt:[Secure the Runtime]

tt:[33.03.138]
|A new field, last-connected, has been added to each Defender stats log. This field records the last confirmed connection time between the Defender and the Console, even when the Connected flag is set to false. The timestamp is represented in epoch seconds (UTC), providing customers with a reliable way to track connection history.
|===

[#intelligence-stream-updates]
=== Intelligence Stream Updates
[cols="30%a,70%a"]
|===
|*Feature*
|*Description*
|Enhancements to Vulnerability Reporting for Red Hat Enterprise Linux (RHEL) Versions 8 and 9
//CWP-30827

|===
tt:[Secure the Runtime]

[#policy-updates]
=== Policy Updates
tt:[33.03.138]
|To ensure accurate vulnerability reporting, Intelligence Stream will include RPM module and stream information for RHEL in the reports. This approach improves detection of vulnerabilities and ensures that all associated RPM packages installed by a module are examined during the scan.

[cols="50%a,50%a"]
|===
|*Policy Updates*
|*Description*
*What are RPM Modules and Streams?*

|===
In Red Hat Enterprise Linux (RHEL), an RPM module is a collection of related RPM packages that represent a software component, such as an application, its dependencies, and helper utilities. Starting with RHEL 6 and 7, modules replaced the Software Collections mechanism.

Modules are structured in the following way:

[#new-compliance-benchmarks-and-updates]
=== New Compliance Benchmarks and Updates
* *Module Streams*: Virtual repositories within the AppStream repository. Each stream corresponds to a specific version of the module and receives independent updates.
[cols="50%a,50%a"]
|===
|*Compliance Benchmark*
|*Description*
* *Stream Activation*: At any time, only one stream of a module can be active, meaning only one version of a component can be installed on a system.
|===
For example, the notation `python39:3.9/python39` indicates the module `python39`, the stream `3.9`, and the source package `python39`.

[#rest-api-updates]
=== REST API Updates
*Enhancements to Vulnerability Reporting*

[cols="37%a,63%a"]
|===
|*Change*
|*Description*
* *Module-Based Vulnerability Identification*: Scans will report vulnerabilities based on the module and stream configuration. This ensures accurate detection and avoids false positives or false negatives caused by discrepancies in versioning or backported fixes.
* *Inclusion of RPM Module Metadata in Scan Results*: The enhanced implementation associates RPM packages with their respective modules and streams. The Prisma Cloud console will include this module information in vulnerability scan results.
*Benefits of Module-Aware Vulnerability Reporting*

* *Improved Accuracy*: Matches CVE fixes to the correct module stream.
* *Reduced False Positives*: Avoids misreporting of vulnerabilities fixed in older streams.
* *Comprehensive Coverage*: Links all RPM packages installed by a module to its vulnerabilities.
|Enhanced Vulnerability Reporting for NuGet Packages
//CWP-49786

tt:[Secure the Runtime]

tt:[33.03.138]
|Previously, the scanning process included NuGet packages listed in the `.deps.json` files, which were essential for the runtime environment but not related to the application itself. These unrelated packages result in false positives in vulnerability reporting.

With this enhancement, the scanning process excludes runtime-specific dependencies that are not directly related to the application. This provides a more accurate view of vulnerabilities directly associated with the application, and reduces false positive alerts.

*NOTE*:

* This enhancement requires upgrading Defenders to the latest version.
* The updated Defender accurately identifies package dependencies, which leads to fewer false positives.
* Older Defender versions will remain unaffected by this change, and their behavior remains unchanged.
|===

//[#new-features]
//=== New Features

//[cols="50%a,50%a"]
//|===
//|*Feature*
//|*Description*

//|===

//[#policy-updates]
//=== Policy Updates

//[cols="50%a,50%a"]
//|===
//|*Policy Updates*
//|*Description*

//|===


//[#new-compliance-benchmarks-and-updates]
//=== New Compliance Benchmarks and Updates

//[cols="50%a,50%a"]
//|===
//|*Compliance Benchmark*
//|*Description*

//|===

//[#rest-api-updates]
//=== REST API Updates

//[cols="37%a,63%a"]
//|===
//|*Change*
//|*Description*


//|===

0 comments on commit 1b2d519

Please sign in to comment.