StackHawk Documentation StackHawk Logo HawkDocs

No results found

Try different keywords or check your spelling

Search documentation

Find guides, API references, and more

esc

Changelog

Tracking updates to the StackHawk platform and HawkScan since 2019

June 29, 2020

HawkScan (0.7.2)

Added

Header Replacer Support

Enables manipulation of request headers to better support apps running behind a proxy

Added

GraphQL Config Section

Support for tuning the GraphQL introspection process

Added

Rate Limiting Controls

Provides more control over the aggressiveness of the scanning capability

Added

Kotlin Scripting Support

ZAP open source contribution for Kotlin support

Added

Passthrough Config Support for ZAP

Supports advanced ZAP configuration via StackHawk YAML

Improvement

GraphQL Introspection

More support for enumeration types and improvements to the test query builder

Improvement

Flexible logging control for ZAP

Adds support for debug logging

Improvement

Transparent localhost proxy instead of url rewriting

Better support for scanning localhost networking scenarios and reverse proxies

June 19, 2020

StackHawk Platform

Added

Paths tab

Assess completeness of scans by reviewing all paths scanned by HawkScan

Added

Integrations

New links to Concourse CI and Github Actions HawkDocs

Improvement

Findings Management

Bulk controls UI improvements, findings table UI improvements, and findings are sorted alphabetically

Improvement

Findings Management Alert Rules

Alert rules are now specific to request method

Improvement

Scans Table

Pagination controls are accessible at the top of the Scans table

Improvement

This Announcement Panel!

See specific changes for HawkScan and StackHawk platform

Fixed

Applications Page Results

See up to 100 applications on Applications page

Fixed

Invite users popup UX fixes

Fixed

URI Truncation

URI truncation in many places throughout the application for readability

Fixed

Validate Findings

curl command generated with double quotes around request body

June 6, 2020

HawkScan (0.6.14)

Added

Terminal Output

Scan progress is now printed to the terminal output

Added

GraphQL Querying Improvements

June 5, 2020

StackHawk Platform

Added

StackHawk Authentication

Log in using any email via StackHawk authentication, or OAuth via Google and Github

Improvement

Findings Management

Take action from the Findings Management right panel for triaging your application’s security vulnerabilities

Fixed

App Creation Wizard

Add missing escape characters to downloaded StackHawk.yml from App Creation Wizard

May 29, 2020

StackHawk Platform

Added

This Announcement Panel!

Announcement panel is a source for release notes, social links, docs and submitting feedback

Added

Findings Management

Users may now triage scan findings by marking them as Assigned, Risk Accepted or False Positive

Added

Scans List Table

As part of Findings Management, the scan list will now reflect new findings (not yet triaged) and a count of triaged findings

Improvement

Browser Support and Logout Notification

Users on unsupported browsers will see a new informational page, and users logged out due to inactivity will be notified via toast notification

Improvement

Faster Performance for Scan Findings Display

May 14, 2020

HawkScan (0.6.6)

Improvement

Support for GraphQL Union and Interface Types

Improvement

Support OpenAPI and Graphql API Scanning with same Config and App

HawkScan now supports configuration for customers that utilize both OpenAPI spec and GraphQL API scanning

Fixed

Gitlab DAST Report Updates

Customers utilizing the StackHawk integration with Gitlab will now see findings updated in their report dashboard.

May 8, 2020

StackHawk Platform

Added

Curl Attack Regenerator

Users may quickly validate a finding by clicking the “Recreate” button. This generates a curl command that a user may paste into their terminal in debug mode and quickly recreate an attack

Improvement

Improvements to the Getting-Started Page Navigation

Improvement

Scan List Pagination

Improvement

Improvements to Mobile Styling

May 8, 2020

HawkScan (0.6.4)

Added

GitLab CI/CD Service Templates

May 4, 2020

StackHawk Platform

Added

Advanced Slack Integration Configuration

You may now configure updates from specific applications to be sent to specific channels in Slack, ensuring that your teams are only getting updates about the applications relevant to their workflow

Fixed

Logout event percolates across all open tabs

Fixed

Login-timeout redirects will take you to the last requested page instead of the last visited page

Your privacy settings

We use first and third party cookies to ensure that we give you the best experience on our website and in our products.