> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-compute-release-information/features-introduced-in-compute-august-2023.md).

# Features Introduced in August 2023

Learn about the new Compute capabilities on Prisma® Cloud Enterprise Edition (SaaS) in August 2023.

The latest release 31.00.129 is planned for August 20, 2023.

The host, container, and serverless capabilities on the **Compute** tab are being upgraded starting on August 20, 2023. When upgraded, the version will be 31.00.129.

* [Defender Upgrade](#defender-upgrade)
* [New Features in Prisma Cloud Compute](#new-features-prisma-cloud-compute)
* [API Changes](#api-changes)
* [Deprecation Notice](#deprecation-notice)
* See also [Known Issues](/release-notes/prisma-cloud-known-issues/known-fixed-issues.md)

## Defender Upgrade

| **Plan to Upgrade Defender Versions 22.06 and Earlier** | <p>With the v31.00.129 (Newton) release, <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/welcome/support_lifecycle">Defender versions supported (n, n-1, and n-2)</a> are v31.xx.xxx, v30.xx.xxx, and v22.12.xxx.</p><p>To prepare for this update, you must upgrade your Defenders from version v22.06.xx.xxx (Kepler) or earlier to a later version. Failure to upgrade Defenders will result in disconnection of any Defender version below 22.12 such as 22.06.</p> |
| ------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

## New Features in Prisma Cloud Compute

| **Expanded Support for Red Hat’s Non-RPM Content**                                       | <p>The Prisma Cloud Intelligence Stream now includes vulnerability data on non-RPM content from Red Hat, including binaries, Python scripts, JavaScript files, and Java JAR files within layered products like OpenShift. Rather than just flagging these as vulnerable, Prisma Cloud can now leverage Red Hat’s own detailed image analysis, enhancing precision in threat detection.</p><p><img src="/files/F6sDv4OBBdxsSJNRYyrt" alt="" data-size="original"></p> |
| ---------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Support of Registry Tags directly in Compute Collections**                             | Added support for registry labels under collections to enable role-based access control (RBAC). The scan results for deployed images are now segregated with a **Custom label** within collections. This enhancement facilitates the association between the registry and the scanned images pertaining to that registry, along with registry-based role-based access control (RBAC) for improved security and management.                                           |
| **Support for Continuous Integration (CI) Scanning of Images on Linux Using Containerd** | Added the ability for users to run CI scans on Linux using the containerd runtime. This change benefits customers using Kubernetes environments, which no longer support Docker as they need to perform CI scans without Docker.                                                                                                                                                                                                                                     |
| **GKE CIS Compliance Checks for Worker Nodes**                                           | CIS Benchmark for Google Kubernetes Engine (GKE) version 1.4.0 is now supported. This update includes compliance checks for worker nodes.                                                                                                                                                                                                                                                                                                                            |

## Deprecation Notice

| **End of Support for Docker Access Control**             | The Docker Access Control at **Defend > Access > Docker** and Access User role at **Manage > Authentication > Roles** were planned for End of Support in Newton (v31.00.129) as announced in [22.06 Release Notes](https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-06/prisma-cloud-compute-edition-release-notes/release-information/release-notes-22-06#:~:text=Upcoming%20Deprecation%20Notifications). The deprecation is now extended until the next release Newton Update 1 (v31.01.xxx), when the feature will be no longer supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Support for Cloud Native Network Segmentation (CNNS)** | <p>The ability to create CNNS policies that Defenders use to limit traffic from containers and hosts was planned for End of Support in this release v31.00.129. The deprecation notice is now extended until the next major release code named O’Neal (v32.0.xxx). The configuration settings on the console (<strong>Compute > Defend > CNNS</strong>) and the corresponding APIs for CNNS will be dropped in v32.0.xxx.</p><p>Radar has a container and a host view, where you can view the network topology for your containerized apps and hosts respectively, and this will continue to be available.</p><p>List of API endpoints that are no longer supported:</p><ul><li>PUT, <code>{{/api/v\<VERSION>/policies/firewall/network/container}}</code></li><li>GET, <code>{{/api/v\<VERSION>/policies/firewall/network}}</code></li><li>GET, <code>{{/api/v\<VERSION>/audits/firewall/network/container/download}}</code></li><li>GET, <code>{{/api/v\<VERSION>/audits/firewall/network/container}}</code></li><li>GET, <code>{{/api/v\<VERSION>/audits/firewall/network/host/download}}</code></li><li>GET, <code>{{/api/v\<VERSION>/audits/firewall/network/host}}</code></li></ul> |
| **Support for Code Repo Scanning**                       | <p>Scanning your code repositories from the Prisma Cloud Compute Console at <strong>Compute > Monitor> Vulnerabilities > Code repositories</strong> and use of Twistcli for code repo scanning was planned for End of Support in this release v31.00.129. The deprecation notice is now extended until the next major release code named O’Neal (v32.0.xxx), when the support will be dropped.</p><p>You must now use the <strong>Code Security</strong> capabilities on Prisma Cloud to scan IaC templates, code repositories, and CI pipelines for misconfigurations and vulnerabilities.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

## API Changes

| **Support and Identification of Registry Asset in Registry Scan** | <p>Starting with 31.00, the value in the field <strong>type</strong> for an object returned in the API endpoint response <strong>GET, api/vVERSION/registry</strong> is now <strong>registry</strong> instead of <strong>image</strong>.</p><p><strong>31.00 and onwards:</strong> type shared.ScanType Possible values: \[registry,ciImage,container,host,agentlessHost,registry,serverlessScan,ciServerless,vm,tas,ciTas,cloudDiscovery,serverlessRadar,serverlessAutoDeploy,hostAutoDeploy,codeRepo,ciCodeRepo]</p><p><strong>30.03 and earlier:</strong> type shared.ScanType Possible values: \[image,ciImage,container,host,agentlessHost,registry,serverlessScan,ciServerless,vm,tas,ciTas,cloudDiscovery,serverlessRadar,serverlessAutoDeploy,hostAutoDeploy,codeRepo,ciCodeRepo]</p> |
| ----------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-compute-release-information/features-introduced-in-compute-august-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
