> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-code-security-release-information/features-introduced-in-code-security-february-2023.md).

# Features Introduced in February 2023

Learn about the new Code Security capabilities on Prisma® Cloud Enterprise Edition (SaaS) in February 2023.

The following new features or enhancements are available for Prisma Cloud Code Security. These capabilities help agile teams add security checks to their existing IaC (Infrastructure-as-Code) model and enforce security throughout the build lifecycle.

* [New Features](#new-features)

## New Features

| FEATURE                                                                  | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Enforcement Thresholds**                                               | <p>You can now configure enforcement thresholds for Vulnerabilities, Licenses, IaC, Build integrity and Secrets. This update aligns with the three new Code Security modules for IaC Security, Software Composition Analysis (SCA) and Secrets Security. For existing customers, the Enforcement thresholds are mapped to the new categories as follows:</p><ul><li>Images: Impacts on Vulnerabilities.</li><li>Open Source: Impacts on Licenses.</li><li>Supply Chain: Impacts on Build Integrity.</li></ul><p>IaC and Secrets have no impact.</p><p><img src="/files/4FDySljTnnyagFkTyrZW" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Code Editor for Custom Secrets**                                       | <p>In addition to the custom policy for build-time checks, Code Editor now helps you define regular expression patterns for Custom Secrets identified on the Prisma Cloud console. The policy violation for custom secrets will continue to be viewable on <strong>Code Security > Projects</strong>.</p><p><img src="/files/bh8vk8AtFohdaoia0eXs" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Alert Rules for Detecting Drift**                                      | <p>With this release, for Drift Detection (<strong>Code Security > Projects</strong>), you can now add alert rules to identify policy drift violations for account groups and policies to which you would like to receive alerts within your AWS and Azure cloud accounts. From the Prisma Cloud console (<strong>Alerts > Overview</strong>), you can access the alert summary and trace the origin of the drift using the <code>yor\_trace</code> tag viewable on Traceability (<strong>Alerts > Overview > Alert Count > Alert ID</strong>)</p><p><img src="/files/FrtcVKZmveT8jSEkrGRZ" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Projects Enhancements**                                                | <p>"Code Security > Projects" on the Prisma Cloud console is enhanced to help you address security issues in your repositories more easily. It now groups scan results by resources and includes saved views with preset filters that provide contextualized scan results. Each view displays policy violations for a code category so you can prioritize what to fix across all your onboarded repositories.</p><ul><li><strong>Overview</strong>: A centralized view of all your scan results across all code categories with automated solutions.</li><li><strong>IaC Misconfiguration</strong>: See scan results for security issues within resources and remediate the issue using automated solutions on the Prisma Cloud console.</li><li><strong>Vulnerabilities</strong>: See scan results for CVE with severity levels and policy violations that may or may not have dependencies within your code. Remediate the issue by fixing the root or dependent versions automatically recommended on the console.</li><li><strong>Secrets</strong>: See scan results for package security with severity levels of the policy violations to remediate.</li><li><strong>License</strong>: See scan results for licensing when using open-source in your code that may have a dependency.</li><li><strong>Build Integrity</strong>: Make informed decisions from the results of the scans in this category that identify multiple owners for the same repositories on integrated platforms.</li><li><strong>VCS Pull Requests</strong>: A centralized view with automated solutions for all your scan results across open PRs.</li><li><strong>CI/CD Runs</strong>: A centralized view with automated solutions for all your scan results on runs of your integrated repositories. You can also create multiple customized views from the default views or by defining a custom view. To access the capabilities of Projects, you need to enable the <strong>Enhanced</strong> on <strong>Code Security > Projects</strong>.</li></ul><p><img src="/files/YVcGM9AceIbZAVyNn6Ob" alt="" data-size="original"></p> |
| **Code Security Developer-Based Metering Plan**                          | <p>Prisma Cloud is introducing a new developer-based metering plan for Code Security. The plan introduces an a-la-carte model which includes three Code Security modules each using credits per developer.</p><ul><li><strong>Infrastructure as Code (IaC) Security</strong>: The module requires 3 credits per developer to help you with security throughout the infrastructure lifecycle.</li><li><strong>Software Composition Analysis (SCA)</strong>: The model requires 4 credits per developer where developers are equipped to find, prioritize, and fix security vulnerabilities and license compliance issues in open-source dependencies.</li><li><strong>Secrets Security</strong>: The module requires 1 credit per developer to scan all files to prevent exposing API keys, passwords, certificates, tokens, and other sensitive secrets with high fidelity using any of your VCS integrations.</li></ul><p>A credit per developer within each of the modules is a user who actively commits on Git, identified through a unique Git email address with a contribution history to any Git repositories in the last 90 days. Enable one or more Code Security modules for an enhanced shift-left experience on the Prisma Cloud console (<strong>Settings > Code Security Configuration</strong>) You can always choose to reconfigure your licensing configuration during the shift-left experience.</p><p><img src="/files/bcWhhTt9oq8ERFdTehfT" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Manage Network Tunnels for self-hosted version control systems (VCS)** | <p>Establish secure and managed access between your self-hosted version control systems (VCS) and Prisma Cloud using Transporter. After configuring a Transporter in your environment, followed by authentication from Prisma Cloud, Transporter establishes a network tunnel through the WebSocket over HTTPS. A single Transporter on the Prisma Cloud can secure multiple VCS integrations, or you can use multiple Transporters. This feature will be available on request.</p><p><img src="/files/VXd0kJdtzqEIi8h0Vx9M" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-code-security-release-information/features-introduced-in-code-security-february-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
