Skip to main content
October 7, 2026
The following changes were introduced in endorctl:
  • AI model discovery now recognizes current model IDs from OpenAI GPT, Anthropic Claude, Google Gemini and Gemma, and AWS Bedrock-hosted models such as DeepSeek, Mistral, Qwen, and xAI Grok.
  • Fixed Package Firewall policies for coding agents blocking read-only commands when an argument contained a command name, such as rm in --rm or node in node:22.
  • AI SAST environment variables now use the ENDOR_AI_SAST_ prefix, such as ENDOR_AI_SAST_SCAN_BUDGET. The old ENDOR_AISAST_* names still work but log a deprecation warning. Scans also warn about any unrecognized AI SAST environment variable.
  • Added Maven 3.10.0, Rust 1.99.0, and pnpm 12.9.1 to the supported toolchains.
October 5, 2026
The following changes were introduced in endorctl:
  • Fixed Gradle monorepo mode (ENDOR_SCAN_GRADLE_MONOREPO_MODE=true) pairing one module’s build file with another module’s dependencies when org.gradle.parallel=true, which produced wrong findings that changed between scans.
  • Malware policies for coding agents now also check edits to Maven pom.xml and Gradle gradle.lockfile files.
  • Fixed AI model scans, including Hugging Face model scans, failing in the EU region because the default query model was unavailable there.
  • Container scans now report OS package vulnerabilities for images based on Alpine Linux 3.24.
October 1, 2026
The following changes were introduced in endorctl:
  • AI SAST detection now reports fewer false positives, finds more vulnerabilities, and assigns CWE IDs to findings more accurately.
  • Fixed SAST scans that could hang indefinitely. The SAST scanner now stops after 60 minutes and reports an error. Set ENDOR_SCAN_SAST_TIMEOUT to change the limit, or set it to 0 to remove it.
  • When endorctl cannot download or load a dependency call graph, the scan now reports partial success with a call graph error instead of success. The exit code is unchanged.
  • PR scans of projects not hosted on GitHub, such as Azure DevOps projects, no longer search GitHub for the pull request number. Set --scm-pr-id to pass the pull request ID for these projects.
  • Fixed Ruby scans that resolved no dependencies when a committed .bundle/config set BUNDLE_GEMFILE to a missing Gemfile and the repository had no Gemfile.lock.
  • Fixed Scala scans creating a duplicate, wrongly named package, such as _2.12.11 instead of _2.12, when sbt could not generate the dependency tree.
  • When AI SAST fails because your AI provider account does not serve the model, or no enabled key covers it, the error now names the model and provider involved.
  • Fixed empty scan logs for SBOM import runs. Logs from endorctl sbom import are now available with the scan.
  • Added pnpm 12.8.1 to the supported toolchains.
September 29, 2026
The following changes were introduced in endorctl:
  • Malware policies for coding agents now also check edits to dependency manifests and lockfiles, such as package.json, requirements.txt, and go.mod, not only install commands.
  • Agent Governance Block and Ask messages now show the text that matched the policy.
  • Fixed audit-only mode (ENDOR_AI_AUDIT_NO_BLOCKING=true) blocking Ask policies in Cursor and stopping sessions from starting in Claude Code, Codex, and Cursor.
  • Fixed a connection failure behind some TLS-inspecting corporate proxies, such as Palo Alto and F5 appliances. Affected commands failed with an Invalid permissions error.
September 24, 2026
The following changes were introduced in endorctl:
  • AI SAST detection agent findings now carry the True Positive finding tag. The True Positive attribute filter and the AI Analysis Status policy parameter now match these findings.
  • AI SAST detection now applies stricter validation that keeps a finding only when the code shows the claimed security effect. This change reduces false positives.
  • SBOM exports now mark AI models as CycloneDX machine-learning-model components instead of libraries. SPDX exports record the matching sourceInfo.
September 17, 2026
The following changes were introduced in endorctl:
  • PR and diff scans of GitHub and GitLab repositories can now resolve the Git merge-base from a single-branch clone. This is opt-in. To enable it, set ENDOR_SCAN_GIT_SINGLE_BRANCH_CLONE=true in the additional environment variables of a scan profile.
  • Fixed SAST scans on Windows so that --include-path and --exclude-path glob patterns keep forward slashes and match files as expected.
  • Agent Governance now records a mid-session Claude Code configuration change, such as toggling /sandbox, as a CONFIG_CHANGE event instead of a file operation.
September 16, 2026
The following changes were introduced in endorctl:
  • Added the --spec-version flag and the ENDOR_SBOM_SPEC_VERSION environment variable to endorctl sbom export to select the SBOM specification version. Use 1.5, 1.6, or 1.7 for CycloneDX, or 2.3 for SPDX. The defaults are CycloneDX 1.5 and SPDX 2.3.
  • endorctl sbom export now runs every export as an asynchronous job. The synchronous export path was removed.
  • Fixed malware scans leaving temporary directories behind, which could fill the disk on long-lived runners.
  • With Conan scanning enabled, endorctl now treats c and cpp in --languages as Conan projects. To run segment-based analysis on C/C++ projects instead, set --segment-match-languages=c.
  • endorctl now exits with return code 46 (ENDORCTL_RC_FAILED_PRECONDITION) instead of an internal error when the server refuses a request because a precondition is not met.
  • JavaScript phantom dependencies, which your code uses but does not declare in its manifest files, are now reported as unpinned.
  • Fixed pnpm dependencies resolved from a URL or tarball being reported as version 0.0.0. endorctl now reads the version recorded in pnpm-lock.yaml.
  • Maven private package manager integrations now support bearer-token authentication through token_auth. endorctl uses token_auth first, then basic_auth, then the deprecated user and password fields.
  • Scan profiles can now pin a custom Conan version through the C toolchain conan_version setting. Without a pin, endorctl uses Conan 2.28.0.
  • AI SAST now keeps the same CWE label and finding name on unchanged code across repeat scans, such as rescans of the same pull request.
  • AI SAST no longer fails the whole scan when your license runs out of AI credits. The scan keeps results from other scanners and logs a warning to contact your Endor Labs account team.
  • Fixed an issue where AI SAST findings still stored the primary location code snippet when a scan ran with --disable-code-snippet-storage. AI SAST no longer stores any code snippets for those findings.
  • Fixed Agent Governance Ask policies blocking every matched tool call in Codex. An Ask policy now warns the user and tells the agent to get confirmation before the call proceeds. Block policies still block the call.
  • The endorctl MCP server scan tool now accepts a segment_match_languages option, which maps to --segment-match-languages. Set it to ["c"] to run segment matching on C/C++ projects. The languages value c now selects Conan dependency scanning.
  • Fixed Swift scans failing when endorctl installed the Swift toolchain after the Swift 6.4.0 release. endorctl now installs Swift 6.3.3 by default, installs 6.3.1, 6.3.2, or 6.3.3 when .swift-version pins one of them, and resolves a bare 6.3 pin to 6.3.3.
  • Fixed Agent Governance in GitHub Copilot CLI sessions. The session-monitored banner and policy notices now appear in the terminal, events report the Copilot version, and ending a session now sends a session stop event so the active session count decreases.
  • Fixed default scans of C/C++ repositories running call graph analysis over C sources and logging Failed to parse file for each file. C is no longer a default --call-graph-languages value.
September 15, 2026
The following changes were introduced in endorctl:
  • Gradle dependency resolution now uses network timeouts, so scans no longer stall on unreachable registries. The defaults are a 15 second connection timeout, a 30 second read timeout, and 1 retry. You can change them with ENDOR_GRADLE_CONNECTION_TIMEOUT (milliseconds, default 15000), ENDOR_GRADLE_READ_TIMEOUT (milliseconds, default 30000), and ENDOR_GRADLE_RETRY_COUNT (default 1).
  • AI SAST can now scan monitored branches and pull requests that target them when you set ENDOR_SCAN_AI_SAST_MULTI_BRANCH=true. It is off by default.
  • Fixed Bazel scans of bzlmod workspaces that reported no Rust crate dependencies. The scan now reads the crate name and version from the repository name when other target information is unavailable.
September 10, 2026
The following changes were introduced in endorctl:
  • Fixed Go dependency resolution so a replace directive records the module that actually supplies the code and keeps the declared path as its import path. Vulnerabilities, licenses, and visibility for replaced modules now resolve correctly.
  • Added private registry authentication for Poetry. endorctl matches sources in [[tool.poetry.source]] to Package Manager integration URLs and passes credentials to poetry lock and poetry install through POETRY_HTTP_BASIC_<SOURCE>_USERNAME and POETRY_HTTP_BASIC_<SOURCE>_PASSWORD.
  • Compressed the YARA rules embedded in the endorctl binary so endpoint security scanners no longer flag endorctl as malware by string-matching signatures inside it. Malware scan behavior is unchanged.
  • Java 27 now passes the endorctl host check. Supported Java versions for scanning are 11.0.0 up to but not including 28.0.0.
  • Added --package-version-uuids (up to 500 values) and --project-uuids (up to 100 values) to endorctl license-notice-report generate. Exactly one of the three scope flags is required.
  • Markdown license notice reports now use a single flat Components layout and no longer split components into Direct and Transitive sections.
  • Added token_auth support for private PyPI registries with pip, Poetry, and uv. endorctl sends the token as the HTTP Basic password with no username, and for Poetry it sets only the password environment variable. Pipenv does not support password-only tokens.
  • AI SAST scheduled refresh is now on by default. Scheduled scans of the default branch re-evaluate stored findings against current code and guidance. Set ENDOR_SCAN_AI_SAST_REFRESH=false to turn it off.
  • Fixed AI SAST whole-file scans of small source files so that functions inside the file are analyzed. Authorization checks and data flows in resolvers and helper functions are no longer skipped.
  • Container scans now print the findings URL for the scanned container’s package version instead of the project findings URL. If no package version is found, endorctl falls back to the project findings URL.
  • endorctl ai-audit now records the shell command a coding agent runs through an MCP tool, and the Agent Governance events list shows the command instead of only the tool name.
  • Fixed endorctl ai-audit leaving claude.ai connectors unclassified when the session configuration was not cached.
  • Fixed scans erasing annotations that users set on existing findings.
September 7, 2026
The following changes were introduced in endorctl:
  • AI SAST scans now generate exploit and remediation details for high and critical findings in parallel with detection, so scans finish faster. If that step fails, findings are kept without the extra details instead of failing.
  • Fixed AI SAST findings carrying OWASP LLM Top 10 2026 entry tags, such as LLM03:2026, for entries where the weakness is only a contributing cause. Each entry tag now comes only from the weakness’s primary CWE, so filtering by an entry tag no longer returns unrelated findings such as prompt injection.
  • Fixed scans intermittently crashing with panic: send on closed channel while building the call graph for reachability analysis.
September 3, 2026
The following changes were introduced in endorctl:
  • Extended Bazel dependency resolution for rules_apple targets to macOS, watchOS, tvOS, and visionOS scan roots, including watch apps embedded in iOS apps. visionOS support covers visionos_application targets only.
  • Added dependency resolution and call graph support for Gosu and Guidewire projects built with Gradle, including the Guidewire gwb wrapper.
  • Fixed container scans intermittently reporting zero findings when the image’s package inventory could not be read. Such scans now fail instead of reporting empty results.
  • Fixed package scans ignoring Maven repositories configured through package managers, including repositories without an ID, and silently falling back to the default repositories.
  • Fixed Bazel scans degrading to partial success when a target query selected internal rule classes such as _ios_internal_*. Unsupported rule classes are now skipped cleanly.
  • Fixed AI SAST findings disappearing from a project’s default branch. A merge scan no longer deletes stored AI SAST results, and a scan that did not run AI SAST no longer retires AI SAST findings.
  • Fixed AI SAST reporting a file as clean without scanning it on a branch that still has the file after another branch deleted it. Scans now remove cached results for deleted files.
  • AI SAST function summaries, used as context for callers and callees, now describe how each argument is handled and which protections are missing, so they no longer overstate a function’s safeguards.
  • AI SAST now skips source files larger than 2 MiB, non-code files larger than 256 KiB, and files over 64 KiB whose lines average more than 2000 bytes, such as data dumps.
  • Fixed AI SAST being silently skipped on scans started by an SCM app installation with AI SAST enabled, while the other selected scanners still ran.
  • AI SAST findings for weaknesses in the OWASP LLM Top 10 2026 list now carry the OWASP-LLM-Top-10 tag, which you can filter on like OWASP-Top-10.
  • The endorctl MCP server scan tool now requires an absolute path when no root directory is configured, and no longer falls back to the server’s working directory.
  • Fixed Agent Governance hooks storing file content, including secrets masked on the earlier event, in post-file-operation audit events. Post-file events no longer carry file content.
  • Fixed AI SAST silently skipping code that contains invalid UTF-8 bytes, such as Latin-1 encoded files, while still reporting a successful scan.
  • Fixed potentially affected malware findings not being created for JavaScript phantom dependencies, which were incorrectly treated as pinned.
  • Fixed AI SAST scans of large Java repositories crashing while writing or loading a module bundle, caused by Java classes that use self-referencing generic type bounds.
  • AI SAST now validates AI and LLM findings against the 2026 OWASP Top 10 for LLM Applications list and applies all six verification criteria.
  • Agent Governance hooks now record the Claude Code version for each session.
  • Fixed Agent Governance hooks recording a model named unknown for Cursor sessions.
  • Agent Governance hooks now use the pinned model configuration when a new Claude Code session does not report its model.
  • Unverified secret findings now carry the Potentially Valid Secret tag (FINDING_TAGS_POTENTIALLY_VALID_SECRET), and the secrets policy template moves to version 2.1.0.
August 27, 2026
The following changes were introduced in endorctl:
  • JavaScript call graph and phantom dependency logs are now reported as an aggregated diagnostic summary per package instead of one entry per file, which greatly reduces scan log volume.
  • JavaScript scans now report which transitive dependencies are pinned by a lock file for npm, yarn, and pnpm projects.
  • Fixed an issue where private JVM dependencies, including Scala dependencies, were skipped during call graph generation instead of being routed to the JVM analyzer.
  • A partial import scan in JavaScript projects is now reported at info level instead of warn level, because unresolved imports are a normal condition.
  • Fixed an issue where the decommissioned Security Review feature caused scans on unlicensed tenants to report partial success instead of completing successfully.
  • Added the endorctl container diff command, along with the --baseline-context-id, --diff, and --snooze-baseline-findings flags, to show only new and fixed findings relative to a baseline container scan.
  • Added the --hide-platform-credentials flag, which removes Endor Labs platform credentials such as GOOGLE_APPLICATION_CREDENTIALS from the environment of Gradle child processes during a scan.
  • Fixed Gradle authentication failures caused by GOOGLE_APPLICATION_CREDENTIALS being inherited by Gradle child processes.
  • JavaScript scans now record both the resolved version and the declared version range that a lock file lists for each dependency.
  • Fixed scans hanging during Maven dependency resolution by adding transport timeouts and retry limits for unreachable private repositories.
  • Added dependency resolution for iOS and Swift targets built with Bazel by attaching the rules_apple aspect to iOS scan roots.
  • Fixed under-reporting of transitive dependencies in Bazel scans, where deeply nested build event protocol file sets were not traversed completely.
  • Added the ENDOR_SCAN_PR_AI_SAST scan profile environment variable. Set it to false to keep AI SAST off PR and merge scans while scheduled scans still run it.
  • Fixed AI SAST findings persisting after you fixed the code. A scan that finds no issues in a file now removes the findings it no longer reports.
  • Fixed AI SAST reporting files as clean on a non-default branch when another branch had already scanned identical content. Full scans now carry over that branch’s findings for those files.
  • Dependency metadata and findings now include the dependency’s native scope as reported by its ecosystem, such as provided, compile, or test, in the native_scope and target_dependency_native_scope fields.
  • Fixed false positive Sourcegraph token findings for labeled commit SHA assignments and CI variables in secrets scan.
  • Fixed the Claude Code hook suppressing Claude Code’s native permission prompt. The hook now returns no decision when a tool call passes all policies.
  • Container scans now report OS package vulnerabilities for Oracle Linux 10 images and can recommend Oracle Linux 10 as a base image upgrade.
  • MCP server names in the AI inventory no longer include version pins or Docker image tags, and servers launched through URL proxies such as mcp-remote are named after the remote server, so duplicate entries collapse into one.
August 24, 2026
The following changes were introduced in endorctl:
  • Fixed re-scan protection for manually managed ecosystems, such as C and C++, by checking the ecosystem of the existing package version.
  • Fixed an issue where private npm package names could be disclosed to the public registry. endorctl now resolves these packages with npm pack using your own registry credentials.
  • Fixed a crash in SAST scans on Windows caused by an O_NOFOLLOW failure in the bundled OpenGrep binary.
  • Fixed authentication for Google Artifact Registry repositories in Gradle builds by injecting an init script during dependency resolution.
  • Fixed the host compatibility check so that a fourth segment in a Java version string no longer fails the maximum supported version check.
  • Fixed false unpinned dependency findings on legacy .NET projects that use NuGet.
  • Fixed an issue where a pnpm transitive dependency was reported as pinned by the root project’s specification.
  • Fixed a crash in Python and Go dependency resolution for Bazel scans caused by aspect nodes without coordinates, and aligned alias() traversal with the other supported rules.
  • Improved scan performance on large monorepos by using a single-branch Git clone.
  • Added finding count entries to the project summary emitted at the end of a scan.
  • PR scans now filter dependency resolution to the packages affected by the pull request by default, across all supported ecosystems. Set ENDOR_SCAN_INCREMENTAL_DEP_RES to false to restore full dependency resolution on PR scans.
  • Fixed AI SAST terminal output for --diff-scope and PR incremental scans listing previously stored findings outside the requested scope.
  • The AI SAST triage agent now recognizes infrastructure-as-code findings by file path, such as Dockerfile, Terraform, and Puppet files, and evaluates them as configuration instead of data flow.
  • Fixed SAST scans failing to parse Dockerfiles that contain square brackets in shell commands, which left the rest of the file unscanned.
  • Fixed AI SAST finding location links to use the resolved commit SHA instead of the branch name, so the links keep working after a force-push or branch deletion.
  • The default Agent Governance policy that asks before package installation no longer prompts for npm install, pip install -r, or pip install -e . commands that install only the packages the project already declares.
  • The default Agent Governance policy that asks before environment variable export no longer prompts for GIT_AUTHOR_* variables or for variables whose values are paths starting with /, ~, ., or $.
  • Agent Governance now attributes Codex events to the ChatGPT account email and GitHub Copilot events to the GitHub login, instead of the operating system username.
  • SAST findings in SARIF output now include startColumn, endLine, and endColumn, so GitHub code scanning highlights the exact code span.
  • Cursor hook events that do not include an account email now report the operating system login as the user, matching the other supported agents.
  • Fixed a scan warning about multiple affected ranges for vulnerabilities with no fix, such as CVE-2026-0994. Findings now report only the affected range that contains the dependency version.
August 18, 2026
The following changes were introduced in endorctl:
  • Fixed truncation of long custom finding policy output fields, such as Remediation, so that multi-byte characters are no longer split into invalid UTF-8.
August 17, 2026
The following changes were introduced in endorctl:
  • Bug fixes and miscellaneous improvements.
August 14, 2026
The following changes were introduced in endorctl:
  • Fixed empty call graphs for Java-only modules in Gradle projects that mix Kotlin and Java. Gradle modules are now analyzed based on the source files they actually contain, so reachability results for your first-party code are complete again.
  • AI SAST and secrets scans now skip .endorignore.yaml, so example values in the ignore file no longer produce findings.
  • Fixed missing call edges in C/C++ call graphs, which made reachability results incomplete. Call graphs now include calls used as variable initializers and cross-file calls that resolve through header prototypes, including headers included with angle brackets.
August 14, 2026
The following changes were introduced in endorctl:
  • Fixed an issue where one private dependency failing to have its call graph saved aborted the remaining dependencies in the same batch. The other dependencies in the batch are now processed, and the scan reports a partial success instead of failing outright.
  • Fixed non-deterministic phantom dependency discovery in JavaScript scans, so npm phantom dependency findings are now stable across repeated scans of unchanged code.
  • A scan that ends in partial success no longer forces a full code rescan on the next run. Only a failed scan triggers a full rescan, so the next scheduled scan of the same project completes faster.
  • Fixed the startup check that endorctl makes against the Endor Labs API, where two competing five second timers covered the same request and could end it early on a slow network, leaving only a bare context deadline exceeded warning. The check now uses a single ten second deadline.
  • The default Ruby toolchain for scans is now Ruby 3.4 instead of Ruby 3.2, which reached end of life. Pin a different version in your scan profile to keep the previous behavior.
  • Base image remediation no longer recommends upgrade tags for OS releases that are pre-release or have no vulnerability data yet. These tags previously appeared to resolve every finding.
  • A tag passed to --base-image-tag-next or --base-image-tag-latest that names such an OS release is now skipped with a warning, and endorctl falls back to auto-discovery for that candidate. The scan exit code is unchanged.
  • Fixed AI SAST scans failing to save project-level context summaries, which made every scan regenerate the same summary. Summaries are now saved and reused on later scans.
August 13, 2026
The following changes were introduced in endorctl:
  • The PR-incremental dependency resolution filter is now enabled by default for the SwiftPM plugin.
  • The --bazel-include-targets and --bazel-exclude-targets flags now reject Bazel target patterns such as //..., //foo:all, and :*, and fail with an actionable error instead of silently matching no targets. Pass explicit target labels, or use --bazel-targets-query for pattern-based selection.
  • The --report-type flag of endorctl license-notice-report generate now accepts md to export a license notice report in Markdown format, alongside pdf, txt, and html.
  • The BomDependency schema now includes a file_location_remote_paths field that maps each local scanned path in file_locations to the matching path in the dependency’s own upstream source. This field is populated only for dependencies identified by segment matching.
  • Fixed the AI SAST triage agent reusing a cached verdict after the flagged code changed. Changed findings are now re-triaged, and unchanged ones keep their cached verdict.
August 11, 2026
The following changes were introduced in endorctl:
  • Fixed gem extraction for Ruby call graph analysis so that symlinks pointing outside the extraction directory are skipped. Ruby call graphs are opt-in through ENDOR_SCAN_RUBY_CALL_GRAPH.
  • Fixed SAST scans failing on Windows in repositories with large numbers of ignored paths. Paths derived from .gitignore are no longer passed as exclude arguments, because the scan engine already skips ignored files.
  • The PR-incremental dependency resolution filter is now enabled by default for the CocoaPods plugin, so pull request scans resolve only the dependencies affected by the changes in the pull request. Set ENDOR_SCAN_INCREMENTAL_DEP_RES to false to turn it off.
  • AI SAST now generates project-level context summaries by default. The --ai-sast-context-summary flag was replaced by --disable-ai-sast-context-summary (ENDOR_SCAN_AI_SAST_DISABLE_CONTEXT_SUMMARY), which turns the summaries off.
  • AI SAST now retries transient failures when saving a segment’s results, so a brief error no longer blocks the repository index from completing. The incomplete scan cache warning now names the affected files.
  • Fixed AI SAST scans failing when a prompt exceeded the model’s context window. Prompt size is now checked against an actual token count, and segments too large to fit are no longer retried on every scan.
  • Fixed SARIF output reporting an inconsistent rule severity when several findings share a rule ID. The rule now carries the highest severity among its findings, and every code location is still reported as a separate result.
  • Fixed scans of Scala-only repositories failing with java: command not found when the scan profile pins a Java version. The configured Java toolchain is now kept for Scala projects.
  • Fixed Bazel scans of Java, Kotlin, and Scala targets that depend on external repositories declared through module extensions. These dependencies previously got an empty version and a malformed package URL, which stopped the package’s dependency data from being saved.
August 6, 2026
The following changes were introduced in endorctl:
  • Bazel scans now resolve dependency root files from the scanned git ref instead of the state on disk, so a target is correctly attributed to MODULE.bazel or WORKSPACE and no longer reports dependency files that are not part of the scanned commit. Cleanup of obsolete versions also handles nested workspaces.
  • Fixed JavaScript and TypeScript call graph generation to follow imports from .tsx files and to record calls to generator functions, which recovers call graph edges that were previously missing from reachability analysis.
  • Scans now log a warning when environment variables configured in a scan profile are ignored, including names that do not start with ENDOR_, reserved names, and entries with empty values.
  • Container scans now de-duplicate resolved Java dependencies, which removes redundant dependency metadata from the reported results for images with large Java dependency sets.
  • Fixed AI SAST skipping every function when its prioritization index was empty, for example on a first scan. AI SAST now scans all non-trivial functions in that case.
  • Fixed duplicate AI SAST findings for the same code location across rescans. Findings that point at the same sink line now merge even when the reported function name differs.
  • AI SAST now prints a warning when it skips a branch or pull request that does not target the default branch. Removed the hidden --ai-sast-all-releases flag. Use --as-default-branch to override.
  • Fixed AI SAST PR scans keeping stale findings for files that are no longer part of the pull request diff, for example after a rebase.
  • Container scans now select the longest matching pre-scanned base image instead of the first match. When more than one pre-scanned base image matches, use --base-image-name to select one.
  • AI SAST no longer assigns CWEs that MITRE marks as discouraged for vulnerability mapping, so findings receive a more specific CWE.
  • Improved C and C++ call graph accuracy for vendored dependencies. Call graph analysis now recognizes lowercase and reserved-identifier include guards, handles typedefs of primitive types, and links calls to functions declared in headers to their definitions in other source files.
August 4, 2026
The following changes were introduced in endorctl:
  • Fixed --segment-match-languages=c so that host toolchain validation is scoped to C when --languages is not set, allowing C-only scans to run without failing on missing toolchains for unrelated languages.
  • Scala scans now log sbt command output, so a failing sbt command surfaces its build diagnostics in the scan logs.
  • The PR-incremental dependency resolution filter is now enabled by default for the .NET plugin.
  • Fixed a loss of matched file paths when a new package version won a tie-break during dependency resolution, so packages retain all matched files and C function reachability results are accurate.
  • Added the ENDOR_SCAN_DYNAMIC_LIBS environment variable, a comma-separated list of package name substrings that call graph analysis treats as additional entry points for Java frameworks that invoke application code reflectively.
  • Improved call graph generation performance on large scans by removing a forced garbage collection that ran after every call graph stitch.
  • Fixed upgrade impact analysis recommending an upgrade of an unrelated package to fix a vulnerability in a direct dependency. Recommendations for a direct dependency now only suggest upgrading that dependency, and regular Guava releases are no longer treated as pre-release builds.
July 30, 2026
The following changes were introduced in endorctl:
  • Fixed scans of large repositories failing with no error during the repository analytics phase. Scans no longer load the full pull request and commit history of the repository into memory.
July 29, 2026
The following changes were introduced in endorctl:
  • Added the --by-severity flag to endorctl container remediation list-base-image-updates so base image update options can be broken down by the severity of the findings they resolve.
  • Go pull request scans now resolve only the dependencies affected by the changes in the pull request, because the incremental dependency resolution filter is enabled by default for the Go plugin.
  • Fixed an issue where the Go plugin reused a cached package workspace across calls, which could leave linter and license results incomplete. The plugin now materializes a fresh workspace for each call.
  • Scheduled scans now skip re-evaluating packages whose dependency edges and code context are unchanged. This reduces scan time for recurring scans.
  • Fixed dependency resolution for Python uv projects that compute their version dynamically, for example from a Git tag. The root package is now matched by name.
  • AI SAST now prints a summary at the end of each scan with the number of segments scanned, served from cache, and still remaining.
  • AI SAST now skips well-known vendored third-party directories, such as third_party/, 3rdparty/, _deps/, Pods/, and site-packages/, which reduces scan time.
  • Fixed a stack overflow crash when scanning Go code that contains self-referential constructs, such as a function that returns a type it declares locally or an F-bounded generic type.
  • Custom Rego policies can no longer call the http.send, net.lookup_ip_addr, or opa.runtime built-in functions.
  • Updated the remediation guidance for potentially affected malware findings to recommend pinning the package to a version or version range without known malware, because a lockfile alone does not prevent resolving to a malicious version.
July 27, 2026
The following changes were introduced in endorctl:
  • Fixed an issue where the dependency graph and the flat dependency list could fall out of sync when segment-matched dependencies were merged, which caused reachability information to be missing for carried-over dependencies.
  • Fixed an issue where PR scans updated the project scan_time, which delayed scheduled rescans of the default branch. PR scans no longer affect default-branch scan scheduling.
  • Creating or updating a custom or system secret rule now triggers a scheduled full-history rescan, so findings for the new rule appear even on repositories with no recent commits.
  • Fixed inconsistent dependency naming in Bazel scans that use a workspace subdirectory with --bazel-workspace-path, so first-party call graphs are stitched together and reachability is classified correctly.
  • Fixed an issue where findings were re-evaluated for projects that have dependency scanning or GitHub Actions scanning disabled, which produced spurious findings.
  • Fixed an issue where scans of repositories with multiple GitHub Actions packages failed with dependency-resolution errors instead of resolving every sub-package.
  • Fixed an issue where pnpm-lock.yaml was omitted from the resolved dependency_files metadata because lock-file detection matched only the .lock suffix.
  • Python PR scans now apply incremental dependency-resolution filtering by default, which reduces PR scan time. Set ENDOR_SCAN_INCREMENTAL_DEP_RES=false to opt out.
  • Fixed AI SAST finding source links pointing to an older commit after a rescan. Location links now point to the repository version that was evaluated.
  • AI SAST now orders caller, callee, and overload context deterministically, so repeated scans of unchanged code produce more consistent results.
  • Fixed AI SAST skipping scan segments when source code and context exceeded the model’s input limit. Oversized code is now split into smaller segments, and optional context is selected to fit.
  • The maximum Java version supported by endorctl host-check is now 25.0.4.
  • Fixed automated base image scans failing on stale Docker image digests that no longer resolve in the registry. Stale digests are now filtered out before the registry lookup.
  • Improved scan performance for packages whose dependencies are resolved approximately, such as when a build fails, by removing a quadratic slowdown in dependency deduplication on large repositories.
July 22, 2026
The following changes were introduced in endorctl:
  • Added Kotlin support to Bazel scans, so kt_jvm_library, kt_jvm_binary, and kt_jvm_test targets are covered by both software composition analysis and call graph reachability.
  • Fixed Bazel scans that generated malformed queries for projects using Bzlmod repositories.
  • Malware findings are no longer raised for npm and PyPI dependencies when the only overlap between the version constraint and the malicious versions is prerelease versions. For example, a dependency constrained to <2.0.0 is not flagged for malware published only as 2.0.0-beta prereleases.
July 20, 2026
The following changes were introduced in endorctl:
  • Fixed the user interface links printed by local scans so they point to the correct regional cluster. For example, app.eu.endorlabs.com for the EU cluster instead of app.endorlabs.com.
  • Fixed endorctl host-check to detect the Maven wrapper in the project root without requiring the --path flag, so it no longer falls back to the system mvn when a wrapper is present.
  • AI SAST now runs only on scans that target the repository’s default branch. Scans of other branches, and pull requests whose base is another branch, skip AI SAST.
  • Fixed secret validation for OpenAI API keys, so detected keys now report the correct validity status.
July 17, 2026
The following changes were introduced in endorctl:
  • The PR-incremental dependency resolution filter is now enabled by default for the JavaScript plugin. It also honors an explicitly pinned lock file outside the package tree with the environment variable, ENDOR_JS_LOCK_FILE_PATH.
  • Scan logs now show the actual reason a pnpm install failed instead of a generic error.
  • dotnet restore and dotnet build can now resolve Windows-targeted frameworks on non-Windows scan hosts when you set the environment variable, ENDOR_SCAN_ENABLE_WINDOWS_TARGETING.
  • Fixed an issue where credentials injected into .npmrc for dependency resolution could persist in the working tree after a scan.
  • Bazel scans now classify each dependency by its own ecosystem instead of inheriting the target’s language, so dependencies such as Cargo and PyPI packages under one target are classified correctly.
  • AI SAST now traces data flow through every caller in the chain, showing only the call sites and the lines that affect them. This applies to Java, C#, Go, and Python.
  • Malware findings are no longer raised for npm and PyPI dependencies whose version constraint cannot match any known malicious version. For example, a dependency constrained to ^1.0.0 is not flagged for malware published only in versions 2.0.0 and 3.0.0.
July 13, 2026
The following changes were introduced in endorctl:
  • Capped SARIF rule tags to a fixed allowlist of 10 tags in deterministic priority order when exporting to GitHub Advanced Security, preventing silent tag truncation and keeping rule tags consistent across exports.
  • endorctl now compares the CODEOWNERS file hash before updating its record during a scan, so an unchanged CODEOWNERS file no longer triggers unnecessary re-processing and private dependency call graph regeneration.
  • Fixed AI SAST scans failing to save results when a finding’s location or data flow description exceeded 1,024 characters. Long descriptions are now truncated.
  • Fixed AI SAST creating duplicate findings for the same vulnerability across scans of the same commit. The sink function name is now resolved from the source code.
  • Fixed broken AI SAST finding paths and source links for scans run on Windows. File paths in findings and links now use forward slashes.
  • Licenses reported by a package manager are now classified as declared licenses in dependency license results, instead of discovered licenses.
July 9, 2026
The following changes were introduced in endorctl:
  • Fixed a crash in AI security review when a generated code reference had an invalid end line number.
  • Reduced false positives in Infrastructure as Code (IaC) findings by improving the AI evaluator prompt.
  • The PR-incremental dependency resolution filter is now enabled by default for the JVM plugin.
  • Fixed Rust scans to resolve dependencies when a Cargo.toml file inherits workspace fields such as version.workspace and edition.workspace.
  • Fixed the segment scanner to remove stale segment match dependencies when a re-scan finds no valid matches.
  • Fixed an error in license dependency processing caused by overly long SPDX license identifiers.
  • Fixed AI SAST scans failing when the CWE classification prompt exceeded the model’s context window. The classification step now receives a trimmed input and at most three CWE matches per finding.
  • AI SAST finding descriptions now use a more readable layout. The Security Controls, Verification Scorecard, and Severity Scoring sections are collapsible, and severity is computed from the scored factors.
  • Fixed AI SAST describing unindexed callees, such as standard library or dependency functions, with the summary of an unrelated repository function. These callees now show only their name and location.
  • Fixed .NET scans ignoring the SDK version pinned in global.json when the file contained a byte order mark, comments, or trailing commas. endorctl now detects the pinned SDK instead of falling back to the default SDK, so dotnet restore no longer fails.
July 6, 2026
The following changes were introduced in endorctl:
  • Added the --segment-match-languages flag to endorctl scan.
  • Fixed .NET call graph scans that failed on Azure DevOps repositories whose names contain spaces, by sanitizing percent-encoded characters in the temporary clone directory path.
  • Fixed scanning of Azure DevOps repositories that use legacy .visualstudio.com URLs.
  • The --diff-scope flag, which limits AI SAST, SAST, and secrets scans to changed files, is now listed in endorctl scan help. It accepts local or baseline.
  • Fixed AI SAST PR scans that reported no default-branch baseline when the full scan used --exclude-path. Exclude-only filters no longer block the baseline from being recorded.
  • Fixed a regression where AI SAST scans run with --ai-sast-rescan still reused cached results instead of rescanning every file.
  • AI SAST now follows the scan profile’s AI SAST setting for every automated scan, not only webhook scans. ENDOR_SCAN_AI_SAST=false now turns AI SAST off even when ENDOR_SCAN_ENABLE includes ai-sast.
  • AI SAST and SAST scan output is now split by the AI tag. --ai-sast shows AI SAST findings, --sast shows rule-based SAST findings, and enabling both shows both.
  • Fixed Azure DevOps PR scans being skipped for repositories whose name ends in .git.
  • Azure DevOps PR scans now report results as pull request statuses instead of commit statuses, so you can use an Azure DevOps branch policy to block pull requests on Endor Labs results.
  • Fixed AI SAST findings missing OWASP and SANS compliance tags, so policies that filter on these tags now match. Child CWEs now inherit the tags of their parent OWASP categories.
  • The endorctl MCP server now reuses existing endorctl credentials, such as those from endorctl init, instead of prompting for browser authentication. Set ENDOR_MCP_SERVER_AUTH_MODE to force a specific authentication mode.
  • Azure DevOps API requests now retry on HTTP 429 rate-limit responses and honor the Retry-After header.
  • Fixed .NET scans stalling for hours after a build command timed out, when leftover MSBuild or compiler server processes kept the command from exiting.
July 1, 2026
The following changes were introduced in endorctl:
  • Fixed Python dependency resolution failing with uv 0.11 and later, where trailing-space arguments to uv pip show caused “invalid value” errors.
  • Added a native secrets detector for JWK private keys, covering RSA, EC, and OKP keys in both JSON and object-literal formats.
  • Fixed phantom root packages with empty paths appearing in concurrent same-language monorepo scans by ignoring transient file-not-found errors during manifest discovery.
  • Fixed non-deterministic dependency loss in Gradle multi-root repositories.
  • Python dependency-resolution failures now surface the actual uv sync error output instead of a generic exit status 1 message.
  • AI SAST now scales concurrent segment analysis with available CPUs, up to 20 by default. This reduces rate-limit errors that could skip code segments on large repositories.
  • Fixed AI SAST PR scans that reported no default-branch baseline after a full scan ran in CI on a detached commit SHA.
  • Fixed finding_url links in SARIF output pointing to the wrong host for tenants on the EU deployment. The link now follows the configured ENDOR_API endpoint.
  • Exception and action policies can now use a finding’s create time during scan evaluation.
June 26, 2026
The following changes were introduced in endorctl:
  • Fixed a regression that prevented scanning empty git repositories.
  • Ruby scans now capture resolved dependencies from Gemfile.lock.
  • Improved AI SAST scan performance on large repositories through faster segment deduplication and .gitignore matching, and by skipping a slow repository-wide caller search.
  • Fixed AI SAST returning no results on scheduled default-branch scans when automated PR scans were turned off in the scan profile.
  • AI SAST now reports fewer false positives.
  • AI SAST now assigns CWE IDs to findings more consistently.
  • Fixed AI SAST PR scans that stayed blocked on a missing default-branch baseline after an earlier full scan left files marked as in progress.
June 24, 2026
The following changes were introduced in endorctl:
  • Fixed container scans dropping Rust dependencies embedded in binaries that are shipped by an OS package.
June 23, 2026
The following changes were introduced in endorctl:
  • Maven package scans now surface the underlying error when a POM fails to parse.
  • Maven dependency resolution now loads the maven-bundle-plugin extension for OSGi POMs.
  • Ruby scans now import bundler to parse gemspec files.
  • AI SAST dataflow steps now carry the step narrative in a separate description field and keep the source excerpt in snippet.
  • AI SAST no longer rescans from scratch when an SCA step such as the Maven call graph fails. --ai-sast-rescan now rescans only AI SAST, without a full SCA rescan.
  • Fixed vulnerability findings that were identified by a DEBIAN-CVE- alias instead of the preferred GHSA or CVE identifier.
  • Fixed container scans of Debian and Ubuntu images reporting duplicate Java packages when the Maven artifact ID starts with lib, such as libthrift.
June 18, 2026
The following changes were introduced in endorctl:
  • Fixed Azure DevOps PR scans that failed due to a false staleness check.
  • SBOM export by name now returns a clear error when the package version is not found.
  • Secret scans now perform a full rescan when an explicit rescan is requested.
June 16, 2026
The following changes were introduced in endorctl:
  • Fixed PR identification for GitLab and Bitbucket, resolving spurious 401 errors during PR scans.
  • Added the --secret-rules-file flag to endorctl scan for supplying custom secret detection rules.
  • Improved language detection for Rust projects.
  • Python call graph generation now batches large projects by lines of code and available memory.
  • Fixed pnpm scan failures where a package referencing workspace catalog: dependencies could not build its lock file when scanned in isolation.
  • AI SAST scans now use a default time budget of six hours for every project. Set ENDOR_AISAST_SCAN_BUDGET to a duration such as 8h to change it.
  • Fixed SBOM exports failing with version is required when a package version was a Git branch name containing /, such as a Swift branch dependency.
June 10, 2026
The following changes were introduced in endorctl:
  • Superseded PR scans are now cancelled automatically, with a dedicated return code.
  • Deleted package versions are now tracked in scan results and scan history.
  • AI SAST findings now carry compliance tags such as OWASP Top 10 and SANS Top 25, derived from their CWE IDs, matching rule-based SAST findings.
  • Segment-match findings now list the actual matched files, up to 10, as their dependency file paths and locations instead of . or the nearest .csproj file.
June 9, 2026
The following changes were introduced in endorctl:
  • Fixed PR scans on shallow or partial clones, where the merge base could be unreachable and the diff silently fell back to an incorrect comparison. endorctl now deepens the clone to reach the merge base, and reports a clear error if the two branches share no history.
  • Container scans now keep Java components bundled inside JVM application OS packages, such as Jenkins or OpenJDK, and deduplicate only OS packages that repackage the same Maven artifact.
June 8, 2026
The following changes were introduced in endorctl:
  • Added the --include-test-dependencies flag to endorctl sbom export.
  • Pre-commit secret scans now flag only added lines.
  • Expanded secret validation coverage.
  • JavaScript scans now resolve call graphs for private transitive dependencies.
  • Improved Ruby dependency resolution in scans.
  • AI SAST findings now show code owners from your CODEOWNERS file, and their location links no longer contain a doubled slash.
  • Fixed scan logs redacting package coordinates such as mvn://group:artifact@version as if they were URL credentials.
  • The GitHub App token secret rule now detects the new stateless ghs_ token format.
  • Fixed reachability analysis errors when a dependency had an empty stored call graph.
June 4, 2026
The following changes were introduced in endorctl:
  • JavaScript scans can now fetch call graphs for private packages.
  • Improved error handling and return codes for local scans.
  • Added a return code for when the baseline is not found.
  • Secret scanning now applies the global allowlist during file walking for faster scans.
  • Fixed incomplete call graphs on large Go projects, where build metadata could exceed an internal scan buffer and silently drop required build settings.
  • Added a secret detection rule for passwords in PostgreSQL connection strings.
  • Fixed dependency resolution for pnpm projects that require pnpm 11, where the automatically installed pnpm toolchain was not found.
June 2, 2026
The following changes were introduced in endorctl:
  • Added the --dry-run flag to endorctl container registry scan.
  • Fixed the declared license field for compound SPDX expressions.
  • AI SAST findings now expose structured data in spec.finding_metadata.ai_sast_data, including per-section explanations and a source-to-sink dataflow with SCM links.
  • AI SAST now analyzes every code segment with caller and callee context, including file-level segments, not only single functions.
  • Added secret detection rules for Groq, Replicate, xAI, Fireworks AI, LangSmith, Anyscale, Supabase, Buildkite, CircleCI personal and project tokens, Docker Hub personal access tokens, Stripe webhook secrets, Resend, and Salesforce access tokens and consumer keys.
  • Action policies in incremental PR scans now treat a finding as new when its dependency becomes reachable or its importer changes, and compare each secret location against the baseline.
  • Secret validation now covers additional Airtable, Dropbox, Facebook, Heroku, Hugging Face, Netlify, npm, and Slack token rules.
  • Fixed npm token validation reporting valid tokens without the user-profile scope as invalid.
June 1, 2026
The following changes were introduced in endorctl:
  • Added the --os-reachability flag to endorctl container registry scan.
  • Added Harbor as a container registry type option.
  • JavaScript scans now support a custom lock file location.
  • Fixed a JavaScript call graph failure that could cause findings to be deleted.
  • Private SCM dependency resolution across organizations is now enabled by default.
  • Added secret detection rules for Azure AD client secrets (canonical Q~ format) and Azure Storage Account Keys, including a validator.
  • Fixed authentication gaps in .npmrc file handling.
  • GitHub SARIF writes now retry transient 401 errors, with clearer GitHub authentication error classification.
  • SBOM export now skips malformed packages instead of failing the entire export.
  • AI SAST scans that exceed their time budget now keep findings from the code already scanned and log how many segments succeeded. Server-side timeouts near the end of the budget no longer abort the scan.
  • AI SAST now splits Scala and Swift code into function-level segments and ignores comment-only changes in these languages during PR scans.
  • AI SAST now runs twice as many code segment scans in parallel by default, two for each available CPU.
  • AI SAST findings now set sast_rule_id and sast_rule_name to the primary CWE ID and name, so you can group AI SAST findings by rule.
May 26, 2026
The following changes were introduced in endorctl:
  • Fixed a Gradle issue where dependencies that failed manifest discovery were silently dropped, which inflated reported success rates. The resolver now synthesizes a path-derived package name so these scan failures are reported accurately.
  • Fixed SBOM imports where SPDX documents with multiple root packages would silently abort and return zero findings. Multi-root SPDX documents are now normalized to a single root before CycloneDX conversion, so imports succeed and vulnerability matching runs.
  • Fixed SBOM imports missing vulnerabilities for public dependencies listed in the imported SBOM.
  • Fixed private Git dependency resolution failing when the SCM access token contains URL-reserved characters, such as Bitbucket Data Center tokens. endorctl now URL-encodes the token in the Git insteadOf rewrite.
  • Fixed SCM access tokens appearing in endorctl warning logs when Git URL rewriting fails.
May 22, 2026
The following changes were introduced in endorctl:
  • Added environment variable support for the scanned-only and exclude-scanned flags in container registry list, with validation that enforces mutual exclusivity between the flags and their environment variables.
  • Added environment variable support (ENDOR_CONTAINER_COLLECT_*) for the kubeconfig-context, kubeconfig-path, and runtime-type flags in container collect, with early validation of the kubeconfig context and runtime type.
May 19, 2026
The following changes were introduced in endorctl:
  • Dependencies whose license category cannot be determined now report a category of Unknown instead of an empty value, so they filter consistently by license category.
  • AI SAST scans now run within a time budget. When the budget runs out, the scan skips the remaining code and reports findings from the code it already scanned.
  • Set ENDOR_AISAST_SCAN_BUDGET to a duration, such as 4h, to override the default AI SAST scan budget.
  • Fixed the first AI SAST scan of a default branch reusing results from an earlier PR scan instead of running a full baseline scan.
  • AI SAST true-positive findings with high or critical severity now include an exploit reproduction section with the exploit path, reproduction steps, and a sample input.
  • AI SAST findings that are not confirmed in high-impact categories now include a validation outcome that explains which verification checks fell short.
  • AI SAST true-positive findings with medium, high, or critical severity now include remediation guidance as a code diff with a short explanation of the fix.
  • AI SAST incremental and PR scans now include the diff of each changed function in the analysis, so detection focuses on removed checks and newly added sinks.
  • License detection now recognizes GPL-2.0 licenses with the classpath exception instead of reporting them as plain GPL-2.0.
  • Fixed Java toolchain auto-detection for Gradle builds that apply the Java plugin with the plugins { java } shorthand when other DSL blocks appear between them, in both Groovy and Kotlin build scripts.
  • Fixed SARIF output reporting high-severity findings with level note. High-severity findings now use level warning.
  • Fixed container scans failing on images that contain Endor-patched Java libraries with a -endor-latest version. The scan now resolves these packages to their pinned patched version.
  • Fixed Bazel scans of Swift projects ignoring Swift targets generated from protocol buffer definitions.
May 14, 2026
The following changes were introduced in endorctl:
  • Dependency metadata now includes declared and discovered SPDX license identifiers.
  • Added Google Artifact Registry (GAR) support for container registry scanning, including authentication and gar as a --type option on endorctl container registry.
  • The --image and --image-tar flags now apply only to the container scan, instrument, and collect commands. The container registry subcommands no longer accept them.
  • Added a warning message when the default branch is switched during a scan.
  • Fixed call graph generation for Java and Scala to use the JDK at JAVA_HOME before falling back to PATH, so the call graph uses your configured JDK.
  • Bazel targets are now resolved at the start of a scan, improving accuracy of the Bazel package include filter.
  • Fixed C# PR segment-matching to handle workspaces with multiple package versions and non-root baseline versions.
  • Fixed container scan argument validation to check both CLI flags and ENDOR_CONTAINER_SCAN_* environment variables, so env-only configuration is no longer ignored.
  • AI SAST now saves findings as a scan runs. If the scan fails partway, the next scan recovers the findings already saved.
  • AI SAST incremental scans now handle renamed files. Pure renames reuse existing findings at the new path, and renamed files with edits are scanned incrementally instead of triggering a full scan.
  • AI SAST --dry-run scans now require only the shared CWE knowledge store and no longer set up repository vector stores.
  • The endorctl MCP server scan tool now accepts ai-sast as a scan type, including diff_scope scans of local or baseline changes.
  • The --pr flag no longer requires --pr-incremental for AI SAST scans that set --diff-scope.
  • Fixed AI SAST PR scans matching new findings to unrelated baseline findings, which hid new findings as already existing.
May 11, 2026
The following changes were introduced in endorctl:
  • Fixed GitHub Actions dependency resolution failing with a generic error when a workflow pins an action to a commit SHA that does not exist in the action’s repository. The dependency is now reported as not found.
May 8, 2026
The following changes were introduced in endorctl:
  • NuGet dependency scans now extract license information from a package’s LicenseUrl when it is not otherwise declared, improving license coverage for NuGet projects.
  • Fixed AI SAST main-branch scans returning findings from a previous PR scan. Scans with nothing to scan or a partial failure now keep existing findings instead of deleting them.
  • AI SAST no longer runs a separate analysis of agent skill files such as SKILL.md, which shortens scan time.
  • Fixed container scans dropping npm packages bundled inside OS-packaged Node.js applications such as npm and yarn. These packages now appear in the dependency list and SBOM.
  • Fixed container scans not reporting end-of-life status for Alpine Linux images such as Alpine 3.19. The scan now uses the EOL date of the Alpine release line when the exact patch version has none.
May 5, 2026
The following changes were introduced in endorctl:
  • Added the --insecure flag (env var ENDOR_CONTAINER_REGISTRY_INSECURE) to endorctl container registry commands, which skips TLS verification when connecting to self-signed container registries.
  • Renamed the environment variable for --registry-namespace from ENDOR_CONTAINER_REGISTRY_REGISTRY_NAMESPACE to ENDOR_CONTAINER_REGISTRY_NAMESPACE.
May 4, 2026
The following changes were introduced in endorctl:
  • Fixed pnpm workspace detection failing when pnpm emitted WARN lines for unresolvable variables in .npmrc files.
  • Fixed secret policies not matching when a custom secret rule’s name differed from its description. The result name is now sourced from the rule name.
  • Added oci as a supported registry type for container scanning, enabling OCI-compliant registry support.
  • Fixed a race condition that could delete the old default branch when a new default branch was set.
  • Fixed PR-incremental scans over-resolving dependencies on Gradle composite-build repositories. The Gradle resolver now honors the narrowed manifest set.
  • Fixed ENDOR_SCAN_LANGUAGES=typescript not running the JavaScript plugin.
  • Fixed PURL qualification for OS packages found through ELF binary cataloging in distroless images, which prevented false-positive vulnerability matches.
  • Fixed PR-incremental scans to source baseline context from the baseline repository version instead of querying all packages.
  • Deprecated the --registry flag on endorctl container registry. It is now replaced by --host.
  • Fixed PR-incremental Java scans triggering full Gradle resolution when no Gradle manifest survived the PR filter.
  • Fixed include-path validation to reject directory paths without /* or /** when set through environment variables, matching the behavior of the CLI flags and preventing accidental package deletions.
  • Reordered path validation so include and exclude paths are validated before .gitignore paths are applied.
  • Deprecated the --registry-type flag on endorctl container registry. It is now replaced by --type.
  • Fixed AI SAST being skipped on merge-to-main scans of Bitbucket and GitLab repositories, which caused those scans to report no AI SAST findings.
  • AI SAST no longer follows symbolic links to directories when it collects files to scan, which matches how the rest of endorctl handles them.
  • Fixed container registry scans timing out while enumerating image metadata in large registries. Registry scans now also handle registry rate limits during enumeration.
  • Fixed Swift scans failing to install the toolchain when a repository requires more than one Swift version, for example a swift-tools-version in Package.swift and a different version in .swift-version.
  • endorctl container registry commands now treat an empty registry host as Docker Hub.
  • Fixed the check_dependency_for_risks MCP tool reporting malicious package records as vulnerabilities. It now returns malware and vulnerability IDs separately.
  • Container reachability now accepts Tetragon eBPF events as profiling data. Place a tetragon.ndjson file in the directory you pass to --profiling-data-dir when you run endorctl container scan --os-reachability.
April 27, 2026
The following changes were introduced in endorctl:
  • Fixed a nil-pointer crash in the JavaScript call graph, which could segfault scans of some npm packages.
  • Fixed the scan end time not being recorded on successful workflow scans, which caused the Scanned column to show an incorrect time.
  • Fixed AI security-review findings being silently dropped when the model classified them as new features or other aspect types.
  • Removed the Hugging Face organization scan flags from endorctl scan. Hugging Face organization scanning is now configured through SCM integrations in the UI.
  • Dependency resolution now always runs for full scans and is skipped only for quick scans.
  • Project summary calculation is now capped at 60 seconds for non-cloud scans, preventing scans from hanging.
  • Fixed Yarn workspace SBOMs being non-deterministic, which had caused flapping results and dropped roughly 2,500 transitive development dependencies.
  • AI SAST now supports --diff-scope. Use --diff-scope=local to scan uncommitted local changes, or --diff-scope=baseline to scan files changed against the default branch.
  • AI SAST now supports --dry-run for local diff scans, which reads project context from Endor Labs without uploading findings. With --ai-sast, --dry-run requires --diff-scope.
  • AI SAST now caches per-file scan results and skips files unchanged since the last successful default-branch scan. Only default-branch scans write the cache, and cache reads and writes are batched.
  • AI SAST no longer reports findings whose only issue is a hardcoded secret, and it redacts secret values in finding text. Secrets scanning covers hardcoded secrets.
  • AI SAST scans now stop with an error when your licensed AI credit limit is exhausted, instead of continuing past the failed requests.
  • Fixed AI SAST PR reruns on the same commit returning zero findings while the previous scan was still in progress. A fresh scan now runs instead.
  • The endorctl MCP server now exposes the describe_resource_schema tool.
  • Fixed the get_resource MCP tool timing out when looking up a resource by name.
  • Fixed C# dependencies identified by segment match being marked reachable or unreachable. Their reachability is now reported as unknown.
  • The AI SAST finding policy now has a Minimum AI SAST Severity parameter. Findings are created only for AI SAST results at or above the selected severity.
  • endorctl now supports Java versions up to 25.0.3.
  • The endorctl MCP scan tool now returns a summary by default, with severity counts and top findings. Set scan_options.summary to false to return full results.
April 21, 2026
The following changes were introduced in endorctl:
  • Fixed an issue where credentials and tokens could leak into logs, scan results, and serialized configuration.
  • Fixed duplicate findings that could override scan results when the SBOM context lacked an identifier.
  • Fixed a nil-pointer crash that could occur when checking invalid file or directory paths during a scan.
  • Added an opt-in windowed incremental mode for secrets scans, enabled with SECRETS_USE_WINDOWED_INCREMENTAL, that splits long scans into time windows with per-window checkpoint persistence.
  • Added support for --diff-scope with --secrets, so secrets scans can be limited to changed files.
  • Fixed incremental scans so that deleted files are included when detecting dependency impact.
  • Fixed the host version check to retry on transient HTTP errors, reducing spurious failures.
  • AI SAST now scans code outside functions, such as module-level configuration and templates. Files of 100 lines or fewer are analyzed as a whole.
  • AI SAST PR scans no longer depend on GitHub webhook payloads to compute the PR diff. PR scans without an SCM PR ID are now skipped unless tagged merge-to-main.
  • Improved reachability analysis for languages other than Java and .NET. Methods without a definition in the call graph are now treated as public entry points.
  • Fixed diff scans on divergent branches so that only commits after the merge base are compared, instead of the entire history.
  • Fixed diff scans failing to fetch the base branch on GitLab, Bitbucket, and self-hosted Git servers, or when the remote is not named origin or the branch is passed as origin/main or refs/heads/main.
  • Fixed container registry scans of GitHub Container Registry failing with a 404 error when --registry-namespace is set to a personal username instead of an organization.
  • Fixed container scans of Chainguard and Wolfi images dropping Python packages, such as urllib3, when an unrelated OS package bundled their files. Vulnerabilities for these PyPI packages are now reported.
  • Scans run through the endorctl MCP server now skip admission policy evaluation, so a policy violation no longer blocks findings from being returned to the IDE. CI scans are unaffected.
  • The endorctl MCP server scan tool now accepts the diff_scope option for the secrets scan type, in addition to sast and vulnerabilities.
  • The get_resource MCP tool now accepts an optional fields list of field mask paths, so it returns only the requested parts of a resource and avoids request timeouts on large resources.
  • Fixed container registry scans ignoring --architecture when pulling images. Images are now pulled for the requested architecture.
  • Findings for dependencies discovered through segment matching now carry the FINDING_TAGS_SEGMENT_MATCH attribute, so you can filter them separately.
April 15, 2026
The following changes were introduced in endorctl:
  • The --registry-type flag is now optional for most container registries. Only self-hosted registries still require it.
  • Improved vulnerability matching for Chainguard and Wolfi apk container images through namespace canonicalization.
  • Fixed uv dependency resolution for pyproject.toml package names containing underscores, following PEP 503 normalization.
  • Fixed call graph errors on Yarn Berry Plug’n’Play projects by forcing the node-modules linker.
  • Fixed sbt dependency parsing for Maven version ranges and version evictions in .dot output.
  • The --reauth flag is now marked experimental. Users are directed to credential helpers instead.
  • Fixed Bazel Build Event Protocol nested fileset parsing.
  • GitHub check-run annotations now show correct finding counts for security review after low-severity filtering.
  • Fixed .NET call graph normalization for private packages that have no DLLs.
  • Fixed a crash in the MCP security review tool and wired in aspect-based classification.
  • AI SAST finding descriptions now link code references to the project’s SCM host, such as GitLab, instead of always linking to github.com.
  • AI SAST PR scans now validate flags before scanning. With --ai-sast, --pr requires --pr-incremental, and --pr-incremental requires --pr-baseline or --enable-pr-comments.
  • Fixed AI SAST skipping automated branch scans when automated PR scans were enabled in the scan profile. It now skips them only when automated PR scans are off, with a clearer message.
  • The --publish flag on endorctl container instrument now pushes the instrumented image to the registry automatically after instrumentation.
  • Vulnerability matching now honors the OSV last_affected range field, so versions after the last affected version are no longer reported as vulnerable.
  • Fixed false-positive vulnerability findings for RHEL packages that have multiple module streams, such as postgresql:13 and postgresql:15. Matching now uses the package’s major version to pick the right stream.
  • Fixed Unmaintained Dependency findings being removed inconsistently for packages with an invalid release timestamp. The package creation time now breaks ties between duplicate package versions.
  • Fixed automated non-PR scans receiving PR comment and PR incremental settings from the scan profile, which caused conflicts because those scans have no PR.
  • The endorctl MCP server scan tool now accepts a diff_scope option for SAST scans. Set it to local to scan uncommitted changes or baseline to scan changes against the default branch.
  • The endorctl MCP server scan tool now accepts a languages option to limit a scan to specific languages. C and C++ projects must pass c because C is not auto-detected.
April 9, 2026
The following changes were introduced in endorctl:
  • Bug fixes and miscellaneous improvements.
April 8, 2026
The following changes were introduced in endorctl:
  • Added a --platform flag to endorctl container instrument that accepts a comma-separated list of platforms, so you can instrument container images for multiple architectures such as arm64 and amd64 in a single command while preserving the multi-arch manifest.
  • Improved Bazel Bzlmod scanning to better detect JavaScript dependencies.
  • Faster secret scanning on Linux from an upgraded secret-detection engine with native RE2 regex support.
April 7, 2026
The following changes were introduced in endorctl:
  • Private Git-based dependencies hosted in other GitHub organizations or GitLab groups now resolve for Go, SwiftPM, Python, Node.js, Rust, and Ruby.
  • The AI SAST evaluator now produces more consistent security review results.
  • The default --timeout for endorctl container registry changed from 30s to 0s, so registry scans run without timing out.
  • C is now an officially supported language.
  • AI SAST now assigns CWE IDs by matching each finding’s title against a CWE index, rather than choosing from a fixed list, for more precise CWE classification.
  • Added Yarn 4.13.0 to the supported toolchains.
  • The endorctl MCP server get_resource, scan, and security_review tools now accept an optional namespace input that overrides the server’s configured namespace, so you can work on child namespaces with parent namespace credentials.
  • Fixed JFrog Artifactory container registry scans failing with a 404 error because the repository key was missing from the image path.
April 1, 2026
The following changes were introduced in endorctl:
  • Host checks now gate container operations on Windows and emit a warning when prerequisites are not met.
  • Unable to process dependencies errors now surface under Issues with a Partial Success scan status instead of only appearing in logs.
  • Merge-to-main lookback is now enabled by default, so incremental PR scans consult recent merge-to-main package versions to avoid duplicate findings across pull requests.
  • Bazel scans now fail gracefully on non-executable targets instead of erroring out.
  • Scan requests now complete instead of staying stuck in progress when a GitHub check-run update fails.
  • C# segment scans now handle package versions that use non-native path separators.
  • JavaScript and npm phantom dependencies are now correctly tagged as phantom and marked transitive instead of direct.
  • TypeScript call graph generation now handles race conditions for more reliable scans.
  • AI SAST repository indexing is now resumable. After a failed or interrupted scan, the next scan can start right away and skips items that are already indexed.
  • Container scans now report vulnerabilities for Chainguard images using the Chainguard security advisory feed.
  • Scans now log a warning instead of an error when a vulnerability’s severity cannot be mapped to a finding level.
March 31, 2026
The following changes were introduced in endorctl:
  • Fixed Yarn dependency graphs that contained dangling edges when alias
  • Fixed the Scala fallback path stripping version suffixes from package names, which previously caused scans to be rejected.
  • Yarn version detection now prefers the lockfile format over the installed runtime binary version.
  • AI SAST PR scans now reuse previous results when the latest commit makes only security-irrelevant changes, such as comment or documentation edits, skipping indexing and analysis.
  • JavaScript scans start faster because the plugin now lazy-loads its TreeSitter queries.
  • .NET scans now attempt a solution-level dotnet restore before falling back to per-project restore.
  • The --base-image-scan flag on endorctl container scan now defaults to true, so base image scanning runs by default.
  • Filesystem secret scans now respect the --include-path and --exclude-path flags.
  • Dependency resolution is now correct when a monorepo root and a workspace child share the same package name.
  • .NET scans now suppress the .NET SDK first-run welcome banner, which previously interfered with MSBuild property extraction.
  • JavaScript scans of non-workspace monorepos now check the repository root node_modules when resolving subpackage lockfiles.
  • Fixed gRPC gateway Prometheus label dropping the x-endor-caller header when it is not present.
  • Container scans now identify the base image locally from the image layers first, instead of querying the Docker daemon.
  • Fixed Bazel scans of Swift projects missing some third-party dependency paths.
  • Fixed container scans missing Go dependencies inside binaries that are installed as OS packages.
  • Fixed license scans of large repositories failing because the results exceeded the maximum document size.
  • Fixed endorctl scan on Azure DevOps repositories (dev.azure.com and visualstudio.com) reporting unable to create SARIF result for finding for SAST and secrets findings.
March 27, 2026
The following changes were introduced in endorctl:
  • Bug fixes and miscellaneous improvements.
March 25, 2026
The following changes were introduced in endorctl:
  • Java dependency resolution now requires actual artifact detection. The legacy identification of dependencies without Java artifacts has been removed.
  • Added Python support for Bazel scans through the rules_python aspects plugin.
  • Raised the custom tag maximum length from 63 to 255 characters.
  • Added Swift support for Bazel scans through the rules_swift aspects integration.
  • Python scans now auto detect unlisted .txt files as pip requirements through content analysis, beyond the files passed with the requirements-file option.
  • Increased the default scan timeout from 10 minutes to 30 minutes.
  • Fixed container scans with --project-name where the base image scan used the project name from ENDOR_SCAN_PROJECT_NAME or ENDOR_CONTAINER_SCAN_PROJECT_NAME instead of the flag value.
  • Fixed container scans of base images that reported the image as its own base image.
  • Fixed scan failures caused by corrupted JSON output from package manager commands such as cargo metadata.
  • Fixed base image scans run by endorctl container scan so that they use the same namespace as the parent scan.
March 20, 2026
The following changes were introduced in endorctl:
  • Fixed a failure scanning Java projects that use private registries over mTLS by merging your custom CA into the default truststore, so public and private dependencies both resolve.
  • Lifecycle scripts are now suppressed during dependency resolution for pnpm, Yarn Berry, and Rush installs, preventing arbitrary code execution.
  • .NET scans now evaluate complex MSBuild property expressions using native MSBuild property evaluation, with a static XML fallback.
  • Fixed SARIF output that triggered GitHub Advanced Security warnings. Findings without a CVSS score now fall back to the finding severity, and security-severity uses a plain decimal value such as 7.5.
  • The scan summary finding counts now include both SAST and AI SAST findings when both are enabled, matching the findings table in the Endor Labs user interface.
March 18, 2026
The following changes were introduced in endorctl:
  • JavaScript call graph generation now fails with a clear error when node_modules were not fully downloaded, instead of producing incorrect results.
  • C# builds now preserve the order of imported prop files in .csproj projects, correcting .NET dependency resolution.
  • .NET scans now shut down the MSBuild build server, preventing orphaned worker processes from accumulating between retries.
  • Incremental PR scans now match root-level packages correctly when the baseline uses pr/* version tags.
  • Incremental PR scans now handle segment-match dependencies correctly for C/C++ and C# projects.
  • Fixed AI SAST PR reruns on an unchanged commit reporting zero findings. Reruns on the same commit now reuse the previous findings.
  • When --base-image-scan is set and --base-image-scan-project is not, endorctl container scan now names the base image project after the base image, with the tag or digest removed.
March 16, 2026
The following changes were introduced in endorctl:
  • Reduced the default Maven connect timeout to 30 seconds and read timeout to 60 seconds so scans against slow package repositories fail faster.
  • Added Quay container registry support to the endorctl container registry list and endorctl container registry scan commands.
  • Fixed .NET package name mismatches by assigning unresolved package names to the resolved package and call graph response.
  • Fixed incorrect package names for Python projects that use a dynamic version field in pyproject.toml.
  • Secret scanning of git logs now assumes files are git tracked, so findings from historical commits are included.
  • Java scans now skip the OWASP dependency-check Maven plugin during the mvn install build step, avoiding a 212MB NVD database download.
  • AI SAST scans of agent skills now include bundled files from the skill’s scripts/, references/, and docs/ directories, up to 64 KB per file and 256 KB per skill.
  • Container and SBOM scans now classify Debian, RPM, APK, SBOM, and git dependencies as external instead of internal.
March 10, 2026
The following changes were introduced in endorctl:
  • PR scans now fall back to a full-history fetch when baseline refs are missing, improving baseline comparison reliability.
  • Fixed Bazel scala_library call graph generation to resolve the correct artifact path.
  • Added support for the latest rules_python hermetic toolchain runfile locations in Bazel Python call graphs.
  • Yarn scans now respect the yarnPath and nodeLinker settings in .yarnrc.yml and handle Yarn registry credentials more reliably.
  • Fixed SPDX SBOM import failures caused by temporary path collisions.
  • Fixed false positive package detection where module setup.py files were misclassified as setuptools manifests.
  • Policy validation now checks for typos in customer-authored policies, surfacing clearer validation errors.
  • Fixed endorctl container instrument for images that set a non-root USER. The instrumented image now starts the sensor as root so runtime monitoring works.
March 5, 2026
The following changes were introduced in endorctl:
  • Fixed a crash when normalizing Python package names with malformed coordinates.
  • Fixed a Docker client connection leak that could accumulate during container scans.
  • Fixed missing pedigree information in SBOM output, including patch and purl fields, with purl now used for dependency lookups.
  • Added the endorctl ignore command that adds findings or vulnerability IDs to the ignore file, which dismisses findings during scans.
  • Added the endorctl validate ignore command that validates the ignore file syntax.
  • The Go registry resolver now handles standard library packages, including direct download and metadata.
  • Fixed handling of URL-encoded slashes in function reference versions for .NET and Java call graphs.
  • AI SAST scans now check for the AI SAST license feature instead of the AI Inference license, and they fail with an error when the license is missing.
  • AI SAST now removes duplicate findings within a scan that share the same sink location and primary CWE.
  • AI SAST scans of non-default branches no longer modify the project’s shared AI SAST index, unless --as-default-branch is set.
  • Fixed AI SAST default-branch scans after a PR merge skipping the merged files during reindexing. The scan now diffs from the last indexed commit.
  • AI SAST severity scoring was recalibrated to reduce the number of findings rated critical.
  • AI SAST findings now label each dataflow location as a source, intermediate step, sink, or logical bug.
  • Fixed endorctl validate policy skipping disabled policies when you validate a policy by its UUID.
  • Fixed endorctl container collect failing to generate a reachability report for instrumented images whose entrypoint spawns child processes, such as MongoDB.