Overview

Aqua is expanding vulnerability and package intelligence coverage by introducing support for additional operating system and programming language ecosystems, while also improving package identification and vulnerability matching for existing ecosystems — including enhanced Node.js detection.

This enhancement is available as part of the U14 release.

What is changing

New operating system support

  • Conda-enabled operating systems

New programming language support

  • C/C++
  • Elixir
  • Dart / Flutter
  • Swift
  • Julia

Enhanced existing ecosystem coverage

  • Improved package detection and vulnerability attribution for Node.js packages to improve accuracy and reduce incorrect findings

These enhancements allow the platform to identify, inventory, and assess vulnerabilities across a broader set of application and runtime ecosystems.

Why this change is being made

Organizations are increasingly building and deploying applications using diverse languages and package ecosystems beyond traditional Linux and Java-based workloads. As customer adoption expands across modern development frameworks and data science platforms, broader ecosystem coverage is required to provide complete risk visibility.

This enhancement is designed to:

  • Expand vulnerability coverage across additional programming languages and package formats
  • Improve software inventory visibility within container images and workloads
  • Reduce false positives through more accurate package identification and vulnerability matching
  • Enhance Node.js package intelligence and detection quality
  • Support customers leveraging modern frameworks such as Flutter, Swift, Julia, Elixir, and C/C++-based applications

Customer impact

This enhancement does not introduce changes to existing customer workflows and is fully backward compatible.

Customers will benefit from:

  • Increased visibility into packages and vulnerabilities across newly supported ecosystems
  • Improved vulnerability detection for C/C++, Elixir, Dart/Flutter, Swift, and Julia applications
  • Enhanced software inventory coverage for Conda-enabled environments
  • More accurate vulnerability reporting for Node.js packages
  • Reduced false positives and improved confidence in scan results

Customers using these ecosystems may notice:

  • Additional packages appearing in scan results
  • New vulnerability findings that were previously not detected
  • Improved package metadata and vulnerability attribution accuracy

Important notes on resource changes

  • CPE format changes: New resources will be created (with uniqueID change) and existing resources will be orphaned and deleted
  • Chainguard resource format changes from pkg:/:3.10:... to pkg:/chainguard:3.10:...
  • Composer-vendor changes from pkg:/composer-vendor:*:tecnickcom/tcpdf:6.6.2 to pkg:/php:*:tecnickcom/tcpdf:6.6.2
  • If the same package is available with composer and composer-vendor, reverting between versions may temporarily show duplicate resources on the UI
  • Resource-level acknowledgements for changed CPEs will be removed; customers need to re-acknowledge affected resources. Image and repository level acknowledgements are not affected

Prerequisites

To take advantage of these enhancements, customers must:

  • Upgrade all scanners to the version that includes the U14 release updates
  • Perform a full rescan of existing images, repositories, and workloads to ensure newly supported ecosystems and packages are identified

Failure to perform a full rescan may result in customers not seeing the complete benefits of the expanded ecosystem coverage.

Scanner upgrade to U14 is required.

Frequently Asked Questions

Q: Will my existing scan results change?

A: You may see additional packages and vulnerability findings after upgrading scanners and performing a full rescan. Node.js detection accuracy will also improve.

Q: Do I need to rescan existing images?

A: Yes. A full rescan is required to identify newly supported ecosystems and packages.

Q: Will acknowledgements be affected?

A: Resource-level acknowledgements for resources with changed CPE formats will be removed. Image and repository level acknowledgements are not affected.

Q: Which new languages are supported?

A: C/C++, Elixir, Dart/Flutter, Swift, and Julia, in addition to Conda-enabled operating system support.