What's New
Explore new features added to AppScan® Source and note any features and capabilities deprecated in this release.
What's new in AppScan® Source version 10.10.0
November, 2025
Enhanced and new functionality in AppScan® Source version 10.10.0
- AppScan® Source JRE Upgraded to Java 21.
- AppScan® Source architecture upgrade from 32-bit to a 64-bit for Windows.
- AppScan® Source supports .NET 10 scanning.
- AppScan® Source now supports for PCI DSS v4 report.
- AppScan® Source now supports DISA STIG V6R3 report format.
- Rule updates.
Fixes and security updates for AppScan® Source version 10.10.0
Fixes and security updates are listed here.
Known issues in AppScan® Source version 10.10.0
- When uninstalling AppScan®
Source version
10.10.0 from a Linux environment, you may encounter the
message:
This message can be ignored. The uninstall process completes properly.JVMJ9VM253W Setting the java.compiler system property is obsolete in version 21 and later, use -Xint instead
Capabilities nearing end-of-life or removed as of AppScan® Source version 10.10.0
-
Upgrading from any earlier version of AppScan® Source that uses SolidDB automatically removes all SolidDB-related files from the AppScan® Source installation.
- Tomcat 8 is no longer included in the AppScan® Source installation package.
- Support for Windows 10 will be removed in the next version of AppScan® Source.
- JDK 11 is no longer included in the AppScan® Source installation package.
What's new in AppScan® Source version 10.9.0
June, 2025
Enhanced and new functionality in AppScan® Source version 10.9.0
- AppScan® Source for Analysis now supports external Tomcat configuration.
- AppScan® Source now supports the combination of node-locked and floating licenses.
- Use the AppScan® Source command line interface (CLI) to configure application servers and external JDK.
- AppScan® Source for Development (Eclipse Plug-in) supports Eclipse IDE 2024-06 to 2025-03.
- AppScan® Source supports Red Hat Enterprise Linux versions 8.10 and 9.5
- Language accuracy improvements
Fixes and security updates in AppScan® Source version 10.9.0
Fixes and security updates are listed here.
Known issues in AppScan® Source version 10.9.0
- On Windows installations, the expand icon is not working on the How to fix page of
the AppScan®
Source Eclipse plugin.To workaround this issue, add the following to the eclipse.ini file under
-vmargs:-Dorg.eclipse.swt.browser.DefaultType=edge
Capabilities nearing end-of-life or removed as of AppScan® Source version 10.9.0
- Support for SolidDB/Oracle will be removed in a future version of AppScan® Source. Please make plans now to migrate to data from SolidDB/Oracle toAppScan® Enterprise Server, whether manually or through the database migration utility.
What's new in AppScan® Source version 10.8.0
February, 2025
Enhanced and new functionality in AppScan® Source version 10.8.0
- IMPORTANT: My HCLSoftware portal has replaced the HCLSoftware Download and License Management
Portal
- AppScan® Source versions 10.8.0 and later can be downloaded through the My HCLSoftware portal (MHS) only.
- AppScan®
Source has added support for
licensing through the My HCLSoftware portal (MHS).
All entitlements have been migrated to MHS. Download or configure your license from MHS before upgrading.
Create new deployments in MHS, then assign and activate your license for AppScan® Source. Devices and products that were activated through FNO are no longer valid and will not work.Note: Only the licensing management platform is changed; there are no changes to the license metrics or any additional charges for your licenses migrated to MHS.For more information about licensing using MHS, see Activating the software.
- AppScan® Source supports HTML scanning.
- AppScan® Source supports the Django framework for Python project scanning.
- AppScan® Source supports .NET 9 scanning.
- AppScan® Source supports the 2024 CWE Top 25 Most Dangerous Software Weaknesses report.
- Users can now view properties for all project folders in the Properties view.
- Language accuracy improvements.
Fixes and security updates in AppScan® Source version 10.8.0
Fixes and security updates are listed here.
Capabilities nearing end-of-life or removed as of AppScan® Source version 10.8.0
- AppScan® Source versions 10.6.0 and earlier will reach end-of-support (EOS) by June, 2025. Upgrade to version 10.7.0 or later before June, 2025, to maintain a supported version of AppScan® Source.
- AppScan® Source no longer supports IBM MobileFirst Platform Application scanning.
What's new in AppScan® Source version 10.7.0
Enhanced and new functionality in AppScan® Source version 10.7.0
- Download AppScan® Source from the HCLSoftware Download and License Management Portal or My HCLSoftware (MHS). In future releases, the new My HCLSoftware portal replaces the HCLSoftware Download and License Management Portal.
- AppScan® Source Findings view and reports have a new column for additional CWEs associated with the primary CWE.
- AppScan® Source supports Red Hat Enterprise Linux versions 9.0 and 9.4.
- AppScan® Source supports ESQL.
- AppScan®
Source support scanning PowerShell
(
.ps1) files within Infrastructure-as-Code projects. - AppScan® Source supports Java 21.
- Updates to rules for Angular, ASP, CSS, Dart, Java source code scanner, JavaScript, JQuery, Objective-C, PHP, Python, secrets scanner, TerraForm, TypeScript, and VueJS.
- AppScan® Source Data Access API classpath updated.
Fixes and security updates in AppScan® Source version 10.7.0
Fixes and security updates are listed here.
Changed in AppScan® Source version 10.7.0
HCLSoftware products are undergoing changes in license acquisition and management. For more information, see Licensing Changes Announcement.
Upcoming changes in AppScan® Source version 10.7.0
- AppScan® Source versions 10.6.0 and earlier will reach end-of-support (EOS) by June, 2025.