> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/ce-release-notes/prisma-tm-cloud-compute-edition-release-information/release-notes-34-01.md).

# 34.01 (Build 34.01.126)

The following table outlines the release particulars:

| Build        | 34.01.126                                                        |
| ------------ | ---------------------------------------------------------------- |
| Code name    | Quinn Update 1                                                   |
| Release date | May 18, 2025                                                     |
| Type         | Minor release                                                    |
| SHA-256      | d6e3cdf62f33363d03eeb5f9dcdb315a3b13f245fad40810ac8e454c8281b485 |

Review the [system requirements](https://docs.prismacloud.io/en/compute-edition/34/admin-guide/install/system-requirements) to learn about the supported operating systems, hypervisors, runtimes, tools, and orchestrators.

## Upgrade from Previous Releases

### Upgrade Defenders

With the `v34.00` release, the [supported Defender releases (n, n-1, and n-2)](https://docs.prismacloud.io/en/compute-edition/32/admin-guide/upgrade/support-lifecycle) are `v34`, `v33`, and `v32` respectively. In addition, Prisma Cloud will not restrict the usage of Defender versions or REST API calls from the n-3 releases. So the current release will allow Defenders and REST API calls from release `v31` also. Failure to upgrade Defenders below release `v31`, such as `v30.03`, will result in disconnection of the Defenders from the Console.

However, to maintain full support, you must upgrade your Defenders to a `v32.00` or a higher release.

To summarize, the level of support for the different versions of Defenders is as follows:

* Defender versions 34.xx, 33.xx, and 32.xx have full support
* Defender versions 31.xx are functional (will be able to connect to version 34.00 Console) but support is not available for such Defenders
* Defender versions previous to 31.00, such as 30.03, are neither supported nor functional (cannot connect to version 34.xx Console)

### Upgrade the Prisma Cloud Console

With the `v34.00` release, the [supported Console releases (n, n-1, and n-2)](https://docs.prismacloud.io/en/compute-edition/32/admin-guide/upgrade/support-lifecycle) are `v34`, `v33`, and `v32` respectively.

Defenders from the n-3 release will remain functional as described above.

You can upgrade the Prisma Cloud console directly from any n-1 or n-2 version to n. For example, with `v34` as n and `v33` as n-1, you can upgrade directly from `33.01.137` to `34.00.141`. You can also upgrade directly from an n-2 version (`32.00.161`, `32.01.128`, `32.02.127`, `32.03.123`, `32.04.113`, `32.05.124`, `32.06.113`, `32.07.123`) to `34.00.141`.

## Announcement

| **Feature**                                                             | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ----------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **RedHat Enterprise Linux 10 incompatibility with WAAS Defender Agent** | <p>RedHat <a href="https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.0_release_notes/deprecated_functionality#deprecated-functionality_networking">deprecated iptables in RHEL 9</a> and the upcoming RHEL 10 will not support iptables.</p><p>The WAAS defender agent deployed directly on RHEL10 (as Host Defender), which relies on iptables, is incompatible with RHEL 10 due to this change.</p><p>Containerized varieties of the WAAS Defender will continue to work.</p> |

## Enhancements

| **Feature**                                                                      | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Enhanced fsmon monitoring process**                                            | <p>To enhance the handling of file system events in the runtime, a new version, fsmon\_v2, has been developed. This version improves stability by managing timeouts more promptly and robustly, which reduces bottlenecks and enhances overall stability.</p><p>Starting from this release (version 34.01), fsmon\_v2 is the default file system monitoring process and runs by default when the defender launches.</p>                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Support for Oracle Linux as Base Image**                                       | Prisma Cloud now provides runtime protection for containers that use Oracle Linux as the base layer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Support for mounted paths**                                                    | <p>A new environment variable (<code>HOST\_FIM\_MOUNTS</code>) enables you to specify additional host mounted paths for runtime monitoring. By incorporating these specified paths into all applicable policies, this feature provides enhanced flexibility in monitoring critical mounted paths within your environment.</p><p>The value of this new variable is a colon separated list of the additional mountpoints to track, for example: <code>/mnt/mountpoint1:/mnt/mountpoint2</code>.</p><p>To update the environment variable:</p><ol><li>Add or modify the new environment variable in the deployment file to include the desired mounted paths for monitoring.</li><li>Deploy the Defender with the new environment variables to activate monitoring of the new paths.</li></ol>                                                    |
| **New environment variable for configuring the number of image external labels** | <p>A new environment variable — <code>IMAGE\_EXTERNAL\_LABELS\_CAP</code>, enables configuration of the maximum number of external labels (indirect labels collected by Prisma Cloud) that are allowed for an image. The default value is 100, and the maximum configurable value is 1024. This variable is applicable to both Console and Defenders.</p><p><strong>Important Considerations:</strong></p><ul><li>External labels, such as Kubernetes Namespace and Deployment labels, as well as cloud tags, are collected and stored per container.</li><li>This limit is specific to external labels collect per image and doesn’t impact existing container limitations.</li><li>External labels are not inherent image properties and are not be displayed if a container is not scanned (for example, short-lived containers).</li></ul> |
| **Vulnerabilities and Compliance data available as PDF files**                   | <p>You can now download the data shown on the following pages as PDF files:</p><ul><li>Monitor > Vulnerabilities > Images & Hosts</li><li>Monitor > Compliance > Containers, Images & Hosts</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Runtime protection for SUSE Linux Enterprise Server 15 SP6**                   | Prisma Cloud now supports runtime protection of SUSE Linux Enterprise Server 15 SP6 images.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

| **Feature**                                                         | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **System Requirements: Changes to supported systems and platforms** | <p>The following changes have been made to the system requirements:</p><p><strong>Support added for the following x86 Operating Systems</strong></p><ul><li>SLES 15 SP6</li><li>Talos OS 1.10.1</li><li>Talos OS 1.9.5</li></ul><p><strong>Support removed for the following x86 Operating Systems</strong></p><ul><li>CentOS 7</li><li>RedHat Enterprise Linux 7</li><li>VMWare Photon OS 3.0</li></ul><p><strong>Support added for the following ARM-based Orchestrators</strong></p><ul><li>Google Kubernetes Engine (GKE) autopilot on ARM v1.31.6-gke.1064001</li><li>Oracle Kubernetes Engine (OKE) V.1.32.1</li></ul><p><strong>Support removed for the following ARM-based Orchestrators</strong></p><ul><li>Elastic Container Service (ECS) 1.86.2</li><li>Elastic Container Service (ECS) 1.86.3</li></ul><p><strong>Support added for the following Auto-Defend platforms</strong></p><ul><li>AWS Node.js 22</li><li>AWS Python 3.13</li></ul> |

## API Changes and New APIs

| **Feature**                         | **Description**                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Download Image Scan Results API** | ​A new column, `Cloud Security Agent Hosts`, is added in the Download Image Scan Results API CSV file response. This new field lists the number of integrated XDR Agents in the Prisma Cloud and Cortex XDR integration.                                                                                                                                                          |
| **Support for new agentless APIs**  | <p>The following new API endpoints enable you to set the maximum number of scanners for an agentless account and get the agentless scan statistics.</p><ul><li><a href="https://pan.dev/compute/api/post-agentless-max-scanners/">Agentless Max Scanners</a></li><li><a href="https://pan.dev/compute/api/get-agentless-scan-statistics/">Agentless Scan Statistics</a></li></ul> |
| **Support for a new enum value**    | A new Enum value `gcp-cloud-run-service` has been added to the shared.ScanResultType schema.                                                                                                                                                                                                                                                                                      |

## Deprecation Notices

| **Feature**                         | **Description**                                                                                                                                                                                                                                                                                                                                                                                  |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Deprecation of the CNNS feature** | The ​Cloud Native Network Segmentation (CNNS) feature is deprecated for the enforcement of protection against network threats for both containers and hosts. However, in scenarios where alternative network monitoring modes are unavailable, it can be used only for monitoring, such as radar visibility. The current recommendation is to disable all CNNS-based network monitoring as well. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/ce-release-notes/prisma-tm-cloud-compute-edition-release-information/release-notes-34-01.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
