<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Version Updates Articles - Codenteam</title>
	<atom:link href="https://codenteam.com/category/version-updates/feed/" rel="self" type="application/rss+xml" />
	<link>https://codenteam.com/category/version-updates/</link>
	<description>The AI Diagnostic Lab for Tech Teams</description>
	<lastBuildDate>Mon, 14 Apr 2025 16:05:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://codenteam.com/wp-content/uploads/cropped-Icon-Round-Dark-32x32.png</url>
	<title>Version Updates Articles - Codenteam</title>
	<link>https://codenteam.com/category/version-updates/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Changes in Risk Levels: What to Expect in Codenteam 1.5</title>
		<link>https://codenteam.com/changes-in-risk-levels-what-to-expect-in-codenteam-1-5/</link>
					<comments>https://codenteam.com/changes-in-risk-levels-what-to-expect-in-codenteam-1-5/#respond</comments>
		
		<dc:creator><![CDATA[Fady S. Ghatas]]></dc:creator>
		<pubDate>Thu, 19 Sep 2024 23:44:19 +0000</pubDate>
				<category><![CDATA[Version Updates]]></category>
		<guid isPermaLink="false">https://codenteam.com/?p=238216</guid>

					<description><![CDATA[<p>We're excited to introduce Codenteam 1.5, featuring enhanced risk detection, code analysis, and due diligence across HR Module, the Investors Hub, External Runs and Security modules.</p>
<p>The post <a href="https://codenteam.com/changes-in-risk-levels-what-to-expect-in-codenteam-1-5/">Changes in Risk Levels: What to Expect in Codenteam 1.5</a> appeared first on <a href="https://codenteam.com">Codenteam</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>We’re excited to announce some significant updates coming to Codenteam 1.5, affecting various aspects of the platform, including HR Managers, the Investors Hub, External Runs, and our security framework. These changes will enhance risk detection, code analysis, and due diligence, ensuring smoother and more secure operations across your teams.</p>



<h3 class="wp-block-heading"><strong>What’s Changing?</strong></h3>



<p>The upcoming release introduces modifications to the risk levels across multiple functions, impacting HR Managers, Tech Managers, Security Managers, and investors alike. Here’s a breakdown of the key updates:</p>



<h3 class="wp-block-heading"><strong>Risk Level Adjustments</strong></h3>



<p>In Codenteam 1.5, you’ll see a recalibration of certain risk levels across both static and dynamic code analysis. These changes ensure that risk assessments are more accurate and actionable:</p>



<ol class="wp-block-list">
<li><strong>Injection Detection Confidence Lowered for Static Code Analysis</strong><br>Some injection detection scenarios in static code analysis have had their confidence ratings reduced to <strong>medium</strong>. While this might suggest that these injections are less likely to be exploited, the overall <strong>risk level remains critical or high</strong> to emphasize the potential danger if not addressed.</li>



<li><strong>New Detection Capabilities for Dynamic Application Testing<br></strong>We’re enhancing dynamic testing by introducing the ability to detect <strong>DOM-based Cross-Site Scripting (XSS)</strong> vulnerabilities in <strong>Active Scanning Mode</strong>. This upgrade is particularly useful in external due diligence processes, helping to identify client-side security issues that previously went unnoticed.</li>
</ol>



<h3 class="wp-block-heading"><strong>Critical Code Ownership Risks</strong></h3>



<p>Ownership of code has emerged as a critical factor in security management, especially when linked to ex-employees or singular developers. The following risks have been updated in Codenteam 1.5:</p>



<ul class="wp-block-list">
<li><strong>Ex-Employee Code Ownership of More Than 50% (Company Level)</strong>: This scenario is now classified as a <strong>critical risk</strong>. A company whose codebase is still majority-owned by ex-employees may face significant operational and security vulnerabilities.</li>



<li><strong>Ex-Employee Code Ownership of More Than 50% (Team Level)</strong>: This represents a <strong>high risk</strong>. The knowledge gap and potential access threats pose considerable challenges for teams.</li>



<li><strong>Single-Developer Ownership of Company Code</strong>: If a single developer controls most of the company’s code, it is now considered a <strong>high risk</strong>. A similar risk applies to teams where code ownership is heavily concentrated with one person.</li>



<li><strong>Module Ownership by Ex-Employees</strong>: Any module still owned or managed by ex-employees is flagged as a <strong>critical risk</strong>, given the potential for lingering access or knowledge gaps.</li>



<li><strong>Module Ownership by a Single Developer</strong>: This risk is now rated <strong>high</strong>, as the absence of distributed ownership can lead to operational bottlenecks and possible security threats.</li>



<li><strong>Modules with No Clear Ownership</strong>: If no specific person or team is accountable for a module, it is assigned a <strong>medium risk</strong> rating. While not as severe as other scenarios, this presents a governance issue that could evolve into more serious risks.</li>
</ul>



<h3 class="wp-block-heading"><strong>Specific Changes Impacting Due Diligence, Internal, and External Runs</strong></h3>



<ul class="wp-block-list">
<li><strong>Due Diligence Module (Investors Hub)</strong>: Investors and stakeholders can now gain more comprehensive insight into the codebase with enhanced injection detection for DOM XSS. This will significantly improve the accuracy of external audits and due diligence.</li>



<li><strong>External and Internal Runs</strong>: The adjustments to injection detection confidence levels and the introduction of DOM XSS detection give both internal security teams and external auditors better visibility into potential risks in the codebase.</li>
</ul>



<h3 class="wp-block-heading"><strong>New Tools for HR Managers</strong></h3>



<p>One exciting new feature for HR Managers in Codenteam 1.5 is the ability to access static code analysis results for candidates during the screening process. This change allows HR teams to assess a candidate&#8217;s code quality and security hygiene as part of their recruitment workflow, providing an extra layer of insight before extending an offer.</p>



<h3 class="wp-block-heading"><strong>Preparing for Codenteam 1.5</strong></h3>



<p>These updates bring improvements across the board—from better injection detection and DOM XSS scanning to more nuanced risk classification around code ownership. Make sure to review your internal and external risk management processes to take full advantage of the new capabilities in Codenteam 1.5.</p>



<p>Stay tuned for the official release, and be ready to integrate these powerful tools and insights into your workflows!</p>



<p><strong>Codenteam 1.5 – Empowering Teams with Actionable Risk Intelligence</strong></p>
<p>The post <a href="https://codenteam.com/changes-in-risk-levels-what-to-expect-in-codenteam-1-5/">Changes in Risk Levels: What to Expect in Codenteam 1.5</a> appeared first on <a href="https://codenteam.com">Codenteam</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://codenteam.com/changes-in-risk-levels-what-to-expect-in-codenteam-1-5/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
