IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.
Release Notes Comply (Version 1.3.2)
Tanium Comply 1.3.2
Release Date: September 12, 2017
New Features
- Deploy Now will now rebuild vulnerability report definitions from vulnerability source. Updating source then clicking "Deploy Now" will apply the latest definitions to the report.
- Added the ability to update Comply vulnerability source data from a zip file for air-gapped environments.
- Added the ability to fully modify the schedule on reports. Recurring schedules can be stopped, single-fire reports can be set to recurring, and any other combination.
- Outdated tools can now be brought up to date on all deployments with a single button click.
- Added the ability to search for a list of CVEs across all vulnerability sources.
Other Enhancements
- Added support for CIS-CAT 3.0.40 & 3.0.41
- Custom check scripts and custom ID mapping files can now be downloaded from Comply.
- Report management operations have been consolidated under a single "Manage Report" button. Export Report & Deploy Now can now be accessed from the report list page, and Delete Report can now be accessed from the report view page.
- JOval vulnerability scan performance has been improved.
- CVE count display added to CVE search results.
For more information on which versions of CIS-CAT, jOval, and SCC are supported, see Comply Supported Engines.
Bug Fixes
- Fixed an issue where deployment status indication didn't check specific engine/JRE versions.
- Fixed an issue on Windows endpoint scans where the engine stdout/stderr wasn't properly captured in the log directory.
- Fixed an issue where the CVE count in the list didn't match the count in the source display.
- Fixed an issue where Windows-style line endings could cause custom checks to fail on Linux/macOS.
- Fixed an issue where the upload button was incorrectly enabled with an invalid set of files during JOval engine upload.
- Fixed an issue where the CVE list filter by score would not work correctly.
- Fixed an issue where the stale report removal action would fire immediately despite being provided with a start time.
- Fixed the display of the aggregate refresh time error so it will no longer display 3 decimals of precision.
- Fixed an issue where "undefined" would be displayed in vulnerability report export under certain circumstances.
- Fixed an issue where "null" would be displayed in the UI for the description of a custom ID mapping.
- Fixed an issue where scan results would be returned incorrectly if a rule title contains a linefeed.
Known Issues
- Tanium Comply does not support any benchmarks that require authentication.
- Endpoint computers with less than 2GB of installed RAM may not have enough free memory to run the CIS-CAT engine when evaluating CIS checklists.
- The Setup page incorrectly lists CIS-CAT 3.0.35 as the latest CIS-CAT release. As of this writing, 3.0.41 is the latest CIS-CAT release supported by Comply.