Advisory: Java AutoScan analysis update

Hey everyone,

We’ve found, and resolved, an issue that may have affected dependency retrieval for some Java projects analyzed using AutoScan.

What Happened

From the beginning of May, an upstream dependency-retrieval limitation may have reduced analysis completeness for some Java AutoScan analyses. We have implemented a mitigation to restore normal dependency retrieval.

Impact

  • Some Java projects analyzed with AutoScan may have had incomplete analysis coverage during this period.
  • Following the mitigation, future analyses may identify additional issues in existing code which may lead to quality gates failing. These findings reflect improved analysis coverage and do not necessarily indicate a recent change to your code or a newly introduced risk.
  • Some projects may show no change.

What You Need to Do

No action is required. Please continue to review and address findings through your normal workflows, especially when quality gates fail.

We apologize for any inconvenience this may cause.

2 Likes