Product Update

FossID Workbench 26.2 Streamlines EU CRA Compliance Management

Workbench 26.2 has landed, building on the Audit, Review, Report workflow released in 26.1 to help you answer, “after scanning, how do I address the risks present and manage new ones on an ongoing basis?”

To this end, 26.2 focuses on the Audit and Review stages and improves Onboarding with new permissions and support for SAML SSO. Let’s dive into what’s new, what changed, and where we’re going from here!

A Revamped Security UX

As organizations prepare for the EU CRA’s vulnerability handling and disclosure requirement, a key goal for 26.2 was to simplify CVE triage and VEX creation. To that end, the Vulnerabilities and Security Review pages get a facelift.

More CVE Intelligence inside the UI

Where before you had to leave Workbench for CVE context, 26.2 brings that context directly into the UI of Workbench. Expanding a CVE now shows its description, affected versions, patch or fix versions, and other data points:

  • the CVSS section adds support for CVSS 4.0 and switching between CVSS versions for researching impact metrics
  • CVEs with published GitHub Security Advisories will show a GHSA section with CVE data enriched by GitHub’s Security Team
  • EPSS Scores and CISA KEV indicators for each CVE provide markers to highlight vulnerabilities with increased exploit risk

These data points power filters that allow you to isolate CVEs needing immediate attention, reducing research time and helping you action on CVEs faster.

A Refreshed, More Intuitive, VEX Workflow

Since introducing VEX in 24.3, users have asked questions such as “which Status do I use” or “when do I set a Justification”. To simplify those decisions, 26.2 introduces a questionnaire-like VEX authoring experience that guides users through creating the VEX for each CVE.

As new versions of a codebase are scanned, sometimes vulnerable components carry across versions. To save on repeated triage effort, the VEX Reuse mechanism was improved to first propose scans inside the existing project so you can arrive at the VEX reuse source faster.

Component Aggregation of CVEs

Security Review now has two views: a CVE List and a Vulnerable Components view. Where the CVE list answers “am I affected by this CVE”, the Vulnerable Components view groups CVEs by Component to answer, “which components are vulnerable?”.

While remediation guidance and VEX creation are on a per-CVE basis, the Vulnerable Components view shows you opportunities to fix many CVEs at once. In 26.3, we will add component-level remediation guidance and component-wide VEX actions. Stay tuned!

New Notification Controls

Workbench 26.2 adds a Notification Settings page under the User menu, where you adjust the notifications that you receive from Workbench both in-application and by e-mail.

Besides controlling the types of notifications, you can adjust your new CVE notifications based on severity and affected projects. This grants you more control over what Workbench notifies you about. Notification settings are personal, so your settings don’t affect other users.

Improvements to the Audit Process

The Audit stage of the Audit-Review-Report workflow also got some love in 26.2, fixing quirks from its migration to React in 26.1. As we fixed those, we took the opportunity to make a few improvements.

Global Settings for Ignores and String Matches

Users with permissions to edit Global Ignore and String Match Rules now have two new dedicated settings pages to do so without having to go into the Scan Configuration.

Simplifying Review of Identified Components

For components identified with the signature scan, there are two new behaviors in the Identified Tab aimed at reducing time spent reviewing and undoing identifications:

  • clicking an identified Component highlights in the file tree all files where that component was identified to quickly show you a component’s associated files
  • two new bulk actions – remove component id clears component identifications and unmark identified unmarks files as identified preserving component identifications

Further reducing the time spent to perform and review identifications is a key focus for 26.3.

“Include in Report” Reuse for Dependencies

For Dependencies found with Dependency Analysis, you can now carry over the “Include in Report” decision to new scans. This employs a mechanism like Identification Reuse, where you choose which Project and Scan to reuse this setting from.

New Permissions and Support for SAML SSO

SAML is now supported in Workbench for SSO, and works together with User Groups and SCIM synchronization to provide more complete support for enterprise access management.

Looking Ahead

These are the highlights of Workbench 26.2. For a complete breakdown of everything included in this release, see the Release Notes.

To learn more about Workbench 26.2 or discuss how to maximize these capabilities to move toward ongoing third-party risk management, open a support ticket, contact your account manager, or visit www.fossid.com/contact. We’re here to help.

More Product Information

FossID tools offer many features that help you build a comprehensive inventory of components in your software and more.
Powerful SCA Features

FossID tools offer many features that help you build a comprehensive inventory of components in your software and more.

Secure and Scalable Deployment

FossID’s Hybrid and Offline deployment models support even the strictest data privacy and confidentiality requirements.

Services to Fast-Track Your Success

FossID’s Audit Services team is available to help you accelerate onboarding and adoption of FossID tools in your environment.

Talk to a Software Supply Chain Ninja

Book a discovery call with one of our experts to discuss your business needs and how our tools and services can help.