This week’s roundup covers public Corgea releases from October 1 through October 6, 2026. The updates make it easier to review findings in the Vulnerabilities Workbench, keep SAST findings distinct when more than one CWE appears on the same statement, and direct CLI scans to the right project when projects share a repository.
Top 3 features
1. A simpler Vulnerabilities Workbench
The Vulnerabilities Workbench now has the same filter bar as the project scan page, without the summary tiles. Findings open in the standard issue panels, where you can review evidence, assign a finding, change its disposition, or open the full finding page.
The updated Workbench also has clearer pagination and counts. Project lists show 15 rows per page, while other levels show 20. Bulk actions now focus on assignment and false-positive decisions; other status changes remain available from each finding panel.
2. More reliable SAST finding tracking
Corgea now keeps different CWEs reported on the same code statement as separate SAST findings. Each finding retains its own triage decision, history, detection dates, and explanation, and new findings are identified correctly in scan results and pull request comments.
This also improves how Corgea handles finding merges and incremental scans. When findings merge, Corgea keeps the newest applicable triage decision and records the outcome in history. If an accepted risk has expired or a fixed finding is detected again, Corgea reopens it when no other decision applies.
3. Separate projects for one repository in the CLI
Teams can now target separate projects that point to the same repository by passing an explicit --project-name to the CLI, where the feature is enabled. The scan uses the selected project’s file include and ignore rules.
That gives teams more control when one repository needs different scanning configurations. For example, a project can use include rules for code Corgea would normally skip, while file ignore rules still take precedence when both rules match.
More features and improvements
- Updated Workbench group and project pagination with clearer spacing, totals, numbered page links, abbreviated large counts, and exact count tooltips.
- Updated group permission-change emails with a clearer summary of who made the change and how many permissions changed.
- Deferred Workbench tab counts until after the page renders so they no longer delay the page opening.
- Kept expanded Workbench results and bulk selections consistent when a rescan changes an older finding’s grouping.
- Show an error and restore the previous assignee when an assignment is refused.
- Stop fix generation from repeatedly restarting when a saved fix cannot be loaded, and show a clear error instead.
- Fixed replies to
@Corgeamentions and PR comments for GitHub integrations without Issues read permission. GitHub scans now also handle project names that include the repository owner. - Fixed incremental scans that could drop a finding or leave it unresolved when another CWE remains on the same statement.
- Kept CWEs separate in report uploads, CxOne triage imports, false-positive verdicts, and automatic learning.
- Return a validation error, rather than a server error, for invalid assignee IDs in individual and bulk assignments.
- Fixed Advanced Vulnerability Search when many filter values are selected, keyboard behavior in searchable dropdowns, table scrolling, and policy action menu visibility on smaller screens.
- Improved checkbox, radio button, and switch contrast in light and dark themes, including clearer partial-selection indicators.
- Prepared updated finding fingerprints from stored source code for more consistent matching across scans while preserving issue tracking and triage history.
- Preserved accepted-risk expiry dates, assignees, due dates, and SLA status when incremental scans carry SAST findings forward.
- Prioritized approval suggestions for pending requests on the page being reviewed and stopped agent-submitted requests from receiving a review suggestion.
- Fixed scheduled and manually triggered scans being assigned to the wrong project when multiple projects use the same repository.
- Applied automatic triage rules to matching untriaged findings carried forward during incremental scans and revalidation.
- Applied automatic triage rules when later scans detect older open SAST or SCA findings that do not yet have a triage comment.