Latest version of Sonatype IQ Server version 176 has been released and is freely available for download for all existing users.
This release offers a new experimental configuration for Call Flow Analysis. With this configuration users can force Call Flow Analysis to occur on every scan made with the Sonatype IQ CLI at an application or organizational level.
In order to distinctly identify policy violations occurring while scanning Sonatype Containers, we have introduced a new condition, Sonatype-Container. Users can set the policy constraint Identification Source to the new condition Sonatype-Container, while creating policies.
Notable Bug Fixes
Fix for an issue that caused errors while scanning CycloneDX SBOMs that were generated from Sonatype IQ Server/Lifecycle.
Fix for an issue in Sonatype IQ Server version 173, that blocked the download of quarantined PyPI components even after they were waived.
For more detailed information on release 176 and tracking resolved issues, please refer to the release notes.
Thank you,
Dariush Griffin
Sonatype Lifecycle - Product Manager