<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How it works Application Security: Software Composition Analysis (SCA), Secrets Security Secrets Security in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1220028#M1432</link>
    <description>&lt;P&gt;Yes, of course &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Yes, I have re-integrated my access token and everything seems to be fine, the status of the repositories on Prisma is green and the scan information is displayed when I scan them.&lt;BR /&gt;But previously, in Application Security &amp;gt; Code &amp;gt; Projects, I had selected the repositories I needed and set the code categories: Vulnerabilities, Secrets and saw the presence of about 170 critical vulnerabilities in packages and images. But after I reintegrated GitLab, those 170 vulnerabilities just disappeared.&lt;BR /&gt;&lt;BR /&gt;And I had a question. Could they be outdated and simply disappear after reintegration?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 16:02:16 GMT</pubDate>
    <dc:creator>O.Chentsov</dc:creator>
    <dc:date>2025-02-11T16:02:16Z</dc:date>
    <item>
      <title>How it works Application Security: Software Composition Analysis (SCA), Secrets Security Secrets Security</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1219976#M1430</link>
      <description>&lt;P&gt;Hello, here's the story:&lt;BR /&gt;We have an integration with Git-Lab, and recently the access token expired. We have reintegrated Git-Lab with Prisma, and we noticed that the vulnerabilities that were there a long time ago have disappeared, but not all of them.&lt;BR /&gt;Can anyone explain why this is happening?&lt;/P&gt;
&lt;P&gt;(the information says that the scan is running)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As the official documentation says: &lt;BR /&gt;"For each vulnerability identified in an SCA scan, Prisma Cloud contextualizes it as a Common Vulnerabilities and Exposures (CVE) for open source package managers."&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 08:07:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1219976#M1430</guid>
      <dc:creator>O.Chentsov</dc:creator>
      <dc:date>2025-02-11T08:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: How it works Application Security: Software Composition Analysis (SCA), Secrets Security Secrets Security</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1220020#M1431</link>
      <description>&lt;P&gt;Hi O.Chentsov,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure I am following your question. Did you re-integrate your Gitlab with Prisma with a renewed token?&lt;/P&gt;
&lt;P&gt;Are you asking why the re-integrated Gitlab is showing less findings than before?&lt;BR /&gt;Can you please elaborate?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1220020#M1431</guid>
      <dc:creator>JNeytchev</dc:creator>
      <dc:date>2025-02-11T15:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: How it works Application Security: Software Composition Analysis (SCA), Secrets Security Secrets Security</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1220028#M1432</link>
      <description>&lt;P&gt;Yes, of course &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Yes, I have re-integrated my access token and everything seems to be fine, the status of the repositories on Prisma is green and the scan information is displayed when I scan them.&lt;BR /&gt;But previously, in Application Security &amp;gt; Code &amp;gt; Projects, I had selected the repositories I needed and set the code categories: Vulnerabilities, Secrets and saw the presence of about 170 critical vulnerabilities in packages and images. But after I reintegrated GitLab, those 170 vulnerabilities just disappeared.&lt;BR /&gt;&lt;BR /&gt;And I had a question. Could they be outdated and simply disappear after reintegration?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 16:02:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/how-it-works-application-security-software-composition-analysis/m-p/1220028#M1432</guid>
      <dc:creator>O.Chentsov</dc:creator>
      <dc:date>2025-02-11T16:02:16Z</dc:date>
    </item>
  </channel>
</rss>

