Release 4.26
Release date: August 28th, 2026
Key Benefitsβ
- A Major Release for Security Operations;
- SSL Certificate Management;
- Tag-Driven Risk Score Policies;
- Pull Request Scans and Security Gate;
- GitLab, Bitbucket, and Developer Ecosystem Integrations;
- Practical API Documentation by Language;
- SBOM Visibility;
- AI Pentest Evolution;
- Advanced Vulnerability Filters;
- A New List, Filter, and Navigation Experience;
- Asset and FQDN Management Improvements;
Introductionβ
Release 4.26 is an important Conviso Platform release. It brings together a broad set of capabilities delivered over an extended period, with a shared goal: helping security and development teams make faster, more confident decisions from a single AppSec platform.
This release expands security operations across the full workflowβfrom repository and pull request scanning to remediation, risk management, SBOM analysis, AI-assisted pentesting, and developer tooling. It also delivers a more consistent experience across the Platform's main lists, filters, and navigation.
Highlights
A Major Release for Security Operationsβ
- Strengthens the connection between security findings, source-code workflows, and developer tools.
- Expands risk management with tag-driven policies and more granular Auto-Fix controls.
- Improves visibility into pull request scans, Security Gate verdicts, SBOMs, and AI Pentest executions.
- Unifies the Platform experience with modern filters, clearer navigation, and more consistent list actions.
New Feature
SSL Certificate Managementβ
- Introduced a dedicated SSL Certificate module for managing certificate operations in the Platform.
- Supports SSL credit purchase flows and access controls aligned with user profiles.
- Gives teams a centralized place to manage certificate-related activities alongside their AppSec operations.
Learn more in the SSL Certificates documentation.
New Feature
Tag-Driven Risk Score Policiesβ
- Create Risk Score Policies that automatically apply risk parameters to assets based on their tags.
- Policies can define Business Impact, Attack Surface, and Data Classification while preserving asset values that are not configured by the policy.
- Supports policy activation, editing, deletion, and bulk asset tagging.
- When an asset matches more than one policy, the user can select the applicable policy and persist that choice on the asset.
Learn more in the Risk Score documentation.
New Feature
Pull Request Scans and Security Gateβ
- Added a Pull Requests view for repository assets, with search, filters, run details, branches, commits, duration, and finding summaries.
- Pull Request Scan runs now show their Security Gate outcome directly in the workflow.
- Security Gate policies can evaluate only vulnerabilities introduced by a pull request or include pre-existing vulnerabilities from the target branch.
- Improved Security Gate visibility with scan-to-gate links, severity-level verdict details, scan filters, and results on the asset view.
- Security Gate surfaces are now aligned with the company's contracted plan.
Learn more in the Pull Request Scans documentation and Security Gate documentation.
New Feature
GitLab, Bitbucket, and Developer Ecosystem Integrationsβ
- Added complete GitLab and Bitbucket repository integration flows, including OAuth connection, scope and repository selection, project import, and configuration in the Platform.
- Azure DevOps, GitLab, and Bitbucket integrations now provide repository scan visibility.
- The Conviso AST task is available in the Visual Studio Marketplace for Azure DevOps pipelines. Learn more in the Azure Pipelines documentation.
- The Conviso GitHub Sync Task is available in GitHub Marketplace to import and synchronize assets from external scanners. Learn more in the GitHub Actions documentation.
- Conviso plugins for Visual Studio Code, Visual Studio, and IntelliJ IDEs bring platform capabilities into the development environment, including AI-assisted security guidance, vulnerability remediation support, secure-code suggestions, and access to security requirements without leaving the IDE.
Learn more in the GitLab Repositories documentation and Bitbucket documentation.
Improvements
Practical API Documentation by Languageβ
- Improved the GraphQL API documentation with practical, operation-level examples.
- Examples are available in multiple programming languages, making it easier for development teams to understand request structure, context, identifiers, and expected usage.
- Reduces the effort required to integrate Conviso Platform capabilities into internal tools, automations, and development workflows.
Learn more in the GraphQL API context and identifiers documentation.
New Feature
SBOM Visibilityβ
- Introduced an improved SBOM visualization experience for clearer component and vulnerability analysis.
- Helps development and security teams understand the software inventory behind a finding and remediate with greater confidence, speed, and precision.
Learn more in the SBOM Management documentation.
New Feature
AI Pentest Evolutionβ
- AI Pentest is now organized around reusable artifacts that centralize scope, authentication, documentation, scheduling, and execution settings.
- Added credit-based assessment settings, allowing teams to estimate the credits required for each assessment according to size and depth.
- Added a retest flow for completed AI Pentest projects, with progress and completion feedback in the project view.
- Added guidance to allow traffic from the AI Pentest Agent when configuring a target.
Learn more in the AI Pentest documentation.
Improvements
Advanced Vulnerability Filtersβ
- Added an advanced query builder for Assets and Vulnerabilities, supporting logical
ANDandORgroups. - Redesigned the Vulnerabilities filtering experience with quick presets, a filter dropdown, and a side panel for reviewing and applying complex criteria.
- Added support for filtering Vulnerabilities by multiple branches at once.
- Improved filter state, URL persistence, and bulk actions, making investigation and remediation workflows more efficient.
Learn more in the Vulnerability Management documentation.
Improvements
A New List, Filter, and Navigation Experienceβ
- Modernized the filtering experience across Vulnerabilities, Assets, Projects, Scans, Security Gate, Applications, and Threat Modeling artifacts.
- Search and filters now live in the table toolbar, with grouped fields, active-filter indicators, quick presets, and side panels where applicable.
- Reorganized bulk actions, column settings, and exports to keep list actions close to the data they affect.
- Improved side-menu flyout navigation so submenus remain open while users move the pointer toward them, preventing accidental closures.
- Enhanced multi-select controls with clearer search behavior, loading feedback, and compact handling for long selections.
Learn more in the Asset Management documentation and Vulnerabilities documentation.
Improvements
Asset and FQDN Management Improvementsβ
- Improved FQDN creation and editing with the full asset form, including required domain URLs, classifications, teams, and tags.
- Expanded Auto-Fix configuration so policies can be tailored by asset and vulnerability severity.
- Improved asset management flows with clearer forms and more consistent routing between repository and domain experiences.
Learn more in the Asset Management documentation.
π Access the Conviso Platform to explore these updates in action.
