Devzy v2.13.0 Release Notes
Scheduled scans, optional pull request reviews, per-scan analysis depth, and models chosen per cloud
This release lets you schedule security and compliance scans, keep those scans running while another tool reviews pull requests, and choose how deep each scan should go. Model choices can follow the cloud you use, and sign-in, sessions, and scan completion are more reliable.
New Features
Automate Scan
Security and compliance scans can run on a schedule for a whole workspace or a single repository.
- Weekly, monthly, or custom: pick a day and time in your timezone, or a custom date that can repeat
- Workspace or repository: a repository schedule takes precedence over a workspace-wide one for that repository
- One scan at a time: a scheduled run is skipped while that repository already has a scan in progress
- Paid plans: scheduled scans are available on paid plans. Moving a workspace to the free trial pauses them, and moving back to a paid plan makes them available again
- Plan-change email: workspace administrators are emailed when a plan change affects scheduled scans
Optional pull request reviews
You can turn off pull request review comments and summaries and keep security and compliance scans active. Use this when another tool already reviews your pull requests.
- Review comments and summaries are not posted while the setting is off
- Security scans and compliance scans continue as before
- Closing a pull request still records the outcome
- Turning reviews back on restores the review options underneath
Analysis depth for a single scan
When you start a scan, you can choose how deep that run should go. Scan history records the choice.
- Economy: faster and lower cost
- Balanced: the default balance of quality and cost
- Deep: the strongest available models
- Free-trial workspaces stay on Economy, and the per-scan choice is hidden there
Models per cloud
When a model is available on more than one cloud, you can choose the cloud for the light model and the heavy model. Reviews, scans, and usage follow that choice.
Claude models on Google Cloud
Claude models can run on Google Cloud as well as the other providers you already use, so a team standardized on that cloud can select them there.
Free-trial welcome email
After the first source-control connection on a free-trial workspace, the person who completed setup receives a welcome email. Setup still succeeds if the email cannot be sent.
Command-line access on paid plans
Command-line sign-in and tokens are available on paid plans.
- Free-trial workspaces cannot create tokens or approve a command-line login
- A token created earlier can still be revoked
- New tokens always expire. Choose 7, 30, 90, or 365 days; if you do not choose, the token lasts 90 days
Improvements
Clearer scan activity
The header count is the number of scans in progress, not the number of repositories. A repository running a security scan and a compliance scan shows two entries, each with its own progress and a link to the right report. A finished result stays visible while the other scan is still running.
Scheduled scans in history
Scheduled runs are labeled Scheduled. History names the person who last saved the schedule, or the person who created it.
Fix prompts name the repository
Opening a compliance finding in your editor names the repository and the branch that was scanned, and asks the assistant to stop if a different workspace is open.
Compliance evidence names the commit
A compliance scan records the commit that was actually read, so downloaded evidence matches the code that was assessed.
Cleaner report downloads
Downloaded PDF reports omit the in-editor fix action, which only works on screen.
Scans finish after a restart
A security scan that is still running when the service restarts is picked up and completed, so the report appears instead of the scan staying in progress.
More complete model answers
Models that reason before they answer are less likely to use the whole reply on that reasoning and return a cut-off result.
Stronger access checks
- Claiming a source-control installation confirms the signed-in account owns it
- GitLab connection changes stay limited to the current workspace
- Connecting or disconnecting Salesforce requires an administrator
- Account status is checked on each request, so a deactivated account loses access immediately
- Sign-in on GitHub Enterprise Server uses a verified account email. If that lookup cannot be read, sign-in continues and the email is left blank
- Outbound notifications and source-control calls go only to the expected services
- Pages and downloaded reports use stronger browser protections
Bug Fixes
- Fixed: A repository running two scan types showing as a single activity entry
- Fixed: Scheduled scans showing a blank trigger and an unlabeled source
- Fixed: In-editor fix prompts naming the default branch instead of the branch that was scanned
- Fixed: A finished security scan left looking in progress after a service restart
- Fixed: LinkedIn badge share text for defender badges
- Fixed: Pull request reviews still posting comments after reviews were turned off
Infrastructure
- Security dependency update in a bundled library
- Release updates so scheduled scans are included when the service is deployed