Skip to main content

SaaS Platform Services -- 1.2.135.3

Levo Team
Product & Engineering

Release period: v1.2.135.2 → v1.2.135.3

This release centres on reporting and inventory hygiene: the API Surface report gains the columns and filters teams have been asking for, duplicate API endpoints can now be merged into one, and inactive APIs can be left out of reports entirely. Security testing gets materially more complete — a default levo test run now covers every test category instead of half of them — and web app scans can ask a person for a one-time code mid-scan. DAST evidence is more honest, and MCP connections and identity-provider lookups are fixed for organizations on Keycloak.

Highlights​

  • API Surface report, substantially expanded — New Authentication Mechanism, Created Date, Schema Modified, Last Trace Received, Incoming/Outgoing, External/Internal and PII columns; filtering by environment and exclusion by tag; per-environment presence as individual columns; and third-party applications excluded by default.
  • Merge duplicate API endpoints — Collapse duplicate endpoints into a single endpoint, with the test cases, findings and traces attached to the merged endpoints following the surviving one.
  • Exclude inactive APIs from reports — Endpoints and API Surface reports can now leave out APIs that have received no call within a configurable period, defaulting to six months.
  • Default security test runs now cover every category — levo test without an explicit --categories list previously ran only 13 of the 25 categories Levo supports; it now runs all of them. Read the API Security Testing section before your next production run.
  • Second-factor codes supplied by a person during a DAST scan — Choose "Ask a person" for multi-factor authentication when creating or scheduling a web app scan, and Levo prompts your team for the code while the scan waits.
  • AI-assisted triage on DAST scan details — Triage with AI is now available from a DAST scan's details, and now requires permission to update a vulnerability's status. See Vulnerabilities & Findings for who loses access.

API Discovery & Cataloging​

New Features​

  • Merge duplicate API endpoints — API endpoints can now be merged, so duplicates discovered from different sources collapse into one. Test cases, findings and traces attached to the merged endpoints follow the surviving endpoint, and the published specification is rebuilt to match.

Resolved Issues​

  • Deleting API endpoints can time out or fail when several delete requests for the same endpoints run at once. Deletes now complete under concurrent and duplicate requests.
  • Deleting API endpoints can get stuck retrying, which stalls trace cleanup for the affected environment. The cleanup is now bounded and no longer loops.
  • Endpoint lookups used by API testing time out in environments with very high trace volume. The lookup is now bounded and returns within its time budget.

API Security Testing​

New Features​

  • Test runners behind a proxy reach the target directly — A test run now adds its own target URL to the runner's no-proxy list automatically and per-run, so an internal target your proxy cannot route to is testable without reconfiguring and restarting the runner. Traffic to Levo still goes through the proxy, and the runner declines the exemption if it would also bypass the proxy for your Levo control plane. If your target is reachable only through the proxy, set LEVOAI_AUTO_NO_PROXY_TARGET=false to keep the previous behaviour.

Resolved Issues​

  • levo test run without --categories (or with --categories ALL) runs only 13 of the 25 categories Levo supports, silently omitting whole OWASP API Top 10 classes including broken function level authorization, mass assignment, security misconfiguration, XSS and CSRF. All 25 categories now run. Default scans are therefore more thorough and longer-running, and they now include denial-of-service tests — pass an explicit --categories list if you need to limit what runs against a production target. Existing saved test plans keep the categories they were created with and must be recreated to pick up the new ones.
  • A failing command worker on a test runner can leak workflow pollers indefinitely, exhausting the shared limit and blocking test runs, Check Auth, reachability and replay for every organization until the runner is restarted. Worker recovery now works and is bounded.

Web Application Scanning (DAST)​

New Features​

  • Relayed one-time codes — A web app scan can now source its second factor from a person. Choose "Ask a person" when creating or scheduling a scan, and Levo prompts your team for the code and holds the scan until it arrives, instead of requiring a hard-coded one-time code.

Resolved Issues​

  • DAST vulnerability evidence shows a fabricated "200 OK" for a probe where no response was actually recorded. The status is now reported as unknown, and probes that did capture a response carry its real status and body.
  • A web app that answers a request for /.env with its normal HTML page is reported as a CRITICAL "Environment file" exposure. Sensitive-file findings now show the real response status, headers and body as evidence instead of an empty placeholder, and the false positive is gone.
  • Scan and worker component health heartbeats fail to report for organizations on Keycloak, so DAST component health appears stale. Heartbeats now authenticate correctly.

Vulnerabilities & Findings​

New Features​

  • Triage with AI on DAST scans — AI-assisted triage is now available from a DAST scan's details, alongside the vulnerability, test-run and application views, and its method is served centrally so prompts stay current without a client update. Triage with AI now requires permission to update a vulnerability's status — roles without it, read-only and auditor roles in particular, no longer see the triage button or banner on the vulnerability, test-run and application pages, where it was previously available to everyone. Organizations also need the vulnerability-triage and DAST-scan-triage entitlements enabled, or the prompts will stop and say so.

Resolved Issues​

  • Security findings that should retire after a passing re-test stay open indefinitely. They now retire as expected.
  • Failures to clean up security findings are reported as an empty error. The underlying reason is now stated, and merging services no longer attempts a findings cleanup that could not succeed.
  • Opening an API endpoint or application in a new tab from the Vulnerabilities screen switches you to a different environment. New-tab links now carry the environment you were working in.

Reporting & Compliance​

New Features​

  • Richer API Surface report — The CSV export adds Authentication Mechanism, Created Date, Schema Modified, Last Trace Received and Incoming/Outgoing columns, plus endpoint-level External/Internal, PII and Authentication indicators. The "Metadata" column is now rendered as "External/Internal", third-party applications are excluded by default, and the underlying rollup is faster.
  • Filter the API Surface report by environment and tag — Scope the report to specific environments, or exclude endpoints carrying specific tags. Environment presence is reported as one column per environment rather than a single combined list.
  • Exclude inactive APIs — Endpoints and API Surface reports can now exclude APIs with no call within a configurable period, defaulting to six months. The report generation screen enables this by default; API callers and existing schedules are unchanged unless they opt in.

Resolved Issues​

  • The API Surface report's column picker offers a stale subset of columns rather than every column the CSV export actually renders. It now lists them all.

MCP Server​

Resolved Issues​

  • Levo MCP server connections fail to authenticate for organizations on Keycloak. The MCP setup page now generates a working configuration, and the server accepts the credential on a header that reaches it intact.

Sensors & Deployment​

Resolved Issues​

  • On-prem metrics ingestion hangs and times out when the metrics backend is slow or unavailable. Metrics submissions are now acknowledged immediately, and a submission that fails is retried with the next batch instead of being dropped.

Platform, Administration & Access​

Resolved Issues​

  • Account lookups and email verification resolve a user's identity provider from the caller's provider rather than the user's own token, and lookup failures are silently swallowed. Verification now resolves the provider from the user's own token and reports failures, fixing accounts held on a different provider from the caller.
  • Service account management returns a permission error in organizations that have role-based access control turned off. It now honours that setting.
  • An incorrect internal address for the identity provider can break server-to-server calls for organizations on Keycloak. The address is now correct.