Preventing LDAP Refresh on Startup / Enabling Persisted Cached LDAP Data
Previously, the LDAP data resided in in-memory cache and was lost at server shutdown. Now,
you can enable the cached data to persist after shutdown, so that restarting Fortify Software
Security Center is much faster, especially for large LDAP environments. For more information,
see "Enabling Persistence of the LDAP Cache" in the user guide.
Updated Kubernetes Support
l
Support for Kubernetes 1.23 and 1.24
l
Support for Helm 3.9
Micro Focus Fortify ScanCentral SAST
The following features have been added to Fortify ScanCentral SAST.
Support for Packaging Java 8 Projects
If you have a Java 8 project that fails to build because ScanCentral SAST requires Java 11 to
run, you can set the new SCANCENTRAL_JAVA_HOME environment variable to point Java 11.
After you do, ScanCentral SAST runs correctly, and the build runs successfully with JAVA_HOME
set to Java 8 for the project build.
Upgrade of the Internal H2 Database Engine
The internal H2 database for Fortify ScanCentral SAST was upgraded. As a result, you must run
an associated migration script. For details, see "Upgrading the ScanCentral SAST Controller" in
the Micro Focus Fortify ScanCentral SAST Installation, Configuration, and Usage Guide.
Improved Method for Excluding Files From Scans When Using ScanCentral SAST to
Package Projects
Previously, Gradle, Maven, and MSBuild integration relied on internal build procedure logic to
collect files. The only way to exclude files was either to exclude them from the build file, or use
an additional translation argument (-targs"-exclude...,"), which required that you knew
where the file was to be saved in the ScanCentral SAST working directory.
You can now use the -exclude option directly from the ScanCentral SAST command line to
exclude some files from scans for the Maven, Gradle, MSBuild build tools, and for -bt none. For
details see "Package Command" in the Micro Focus Fortify ScanCentral SAST Installation,
Configuration, and Usage Guide.
Configuring the Name of FPR Files Uploaded to Fortify Software Security Center
The FPR files uploaded to Fortify Software Security Center are named scan.fpr. You can now use
the -fprssc option specify the name to use for generated FPR files uploaded to Fortify Software
Security Center. For details, see "Submitting Scan Requests and Uploading Results to Fortify
Software Security Center" in the Micro Focus Fortify ScanCentral SAST Installation,
Configuration, and Usage Guide.
Micro Focus Fortify Software (22.2.0)
Page 3 of 30