This week’s roundup covers the September 10 public Corgea release. The update puts Corgea Agent in the main navigation, gives administrators a daily view of pending learning recommendations, and adds more context and controls to Advanced Vulnerability Search.

Top 3 features

1. Corgea Agent is now easier to find

Corgea Agent now has its own top-level item in the sidebar. Feedback History has moved into the agent settings, and command palette results make it clearer where to open the agent and manage its configuration.

The agent helps teams inspect findings, analyze scan results, and query vulnerability data from chat or pull request comments. It works with GitHub, GitLab, Azure DevOps, and Bitbucket when the relevant integration and webhooks are configured.

2. Daily digests for agent learning recommendations

Administrators now receive a daily email digest for new agent learning recommendations. The digest summarizes the recommendations and links directly to the pending items, so admins can review them without tracking individual notifications throughout the day.

The update gives teams a regular review point for recommendations while keeping agent settings and feedback history in the same place.

Advanced Vulnerability Search now shows inline details for SCA and container findings. It also adds assignment and status controls for IaC findings, plus clearer filters and layouts on smaller screens.

The search already lets teams investigate findings across scan runs with filters for category, urgency, status, scan type, project, branch, policies, and metadata. Results open in a side panel so reviewers can inspect evidence, remediation guidance, and scan details without losing their active filters.

More features and improvements

  • Improved form readability in light and dark themes.
  • Made reporting charts and empty states more consistent.
  • Restored Create PR for CLI and IDE scans of connected repositories.
  • Added clearer guidance when a scanned branch needs to be pushed before Corgea can create a pull request.
  • Fixed GitHub team membership updates when webhook events omit the team slug.
  • Updated Harness repository discovery to keep accessible repositories when other projects are unavailable or do not have the Code module.
  • Sped up SBOM dependency reprocessing for large dependency trees.
  • Added separate scan-capacity tuning for pull request and full scans.