
We’ve added the ability to create a shortlist of key risks as part of a risk assessment, allowing you to highlight important risks and those requiring follow-up. You can choose to include only key risks as part of your risk assessment report, in lieu of displaying the full list of risks. To learn more see How to complete a risk assessment.
We’ve revised API permissions to allow a finer-grained set of permissions and visibility:
To learn more see UpGuard’s API documentation.
We’ve created specific API endpoints to start monitoring and stop monitoring a vendor. This allows us to follow more established and consistent API design practices as well as restrict the monitoring to only those API Keys that have Vendor Risk Read&Write permissions. In subsequent releases, we will deprecate the “start_monitoring” flag in the /vendor API endpoint and remove that feature:
- The ability to apply labels and tiers;
- A wait for a scan feature that scans the vendor before returning the results;
- Checks on UpGuard licenses maximum Vendor counts.
To learn more see UpGuard’s API documentation.
We’ve added detection for the SysAid product, its version, and associated vulnerabilities, notably CVE-2023-47246 being exploited by the Clop group.