> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2023/features-introduced-in-december-2023.md).

# Features Introduced in December 2023

Learn what’s new on Prisma® Cloud in December 2023.

## New Features Introduced in December 2023

* [Announcement](#announcement)
* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notices](#deprecation-notices)
* [End of Support Notifications](#end-of-support)

## Announcement

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Prisma Cloud Darwin Release** | <p>The <strong>Prisma Cloud Darwin Release</strong> is here for Prisma Cloud environments on app, app3, app.eu, app2.eu except app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.</p><p>With this change, your tenant will be updated with the new intuitive user interface and <a href="https://live.paloaltonetworks.com/t5/prisma-cloud-customer-videos/prisma-cloud-evolution-amp-transformation/ta-p/556596">rich set of security capabilities</a>.</p><p>Connect with your Customer Success team for more details.</p><p>When you are upgraded to the Darwin release, refer to the <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/">Enterprise Edition documentation</a>.</p> |

## New Features

| FEATURE                                                                                                                                                                                                                                     | DESCRIPTION                                                                                                                           |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>IAM Policy Scanner Enhancement</strong></p><p><em><mark style="background-color:orange;"><strong>Secure the Infrastructure</strong></mark></em></p><p><mark style="background-color:orange;"><strong>23.12.1</strong></mark></p> | IAM Policy Scanner now includes enhancements to improve alert accuracy. This may result in some alerts briefly closing and reopening. |

## API Ingestions

The 23.12.1 release does not include any API Ingestions.

## New Policies

| NEW POLICIES                                                               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| -------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **New Policies to Configuration Build Policies**                           | <p>Starting from this release 2 new policies are added to Config policies of subtype Build. Here are the policies:</p><ul><li>AWS CloudFront attached WAFv2 WebACL is not configured with AMR for Log4j Vulnerability</li><li>Software Composition Analysis (SCA) findings</li></ul><p>In addition, 6 new policies integrated with CI/CD Risks are added by default to Prisma Cloud console and visible Governance.</p><ul><li>BitBucket private repository made public.</li><li>Unrotated organization secrets in GitHub Actions.</li><li>Unrotated repository secrets in GitHub Actions.</li><li>CircleCI pipeline uses an unpinned container image.</li><li>Azure Pipelines uses an unpinned container image.</li><li>Secrets found in logs of a GitLab CI pipeline.</li></ul><p><strong>Impact</strong>- Impact- You will view policy violations for these policies on Prisma Cloud switcher <strong>Application Security > Projects</strong> in CI/CD Risks with CI/CD module enabled on <strong>Application Security > Settings</strong>.</p> |
| **Azure Virtual Machine (Linux) does not authenticate using the SSH keys** | <p><strong>Changes</strong> - The policy name is being updated to reflect the latest changes.</p><p><strong>Current Policy Name</strong> - Azure instance does not authenticate using the SSH keys</p><p><strong>Impact</strong>- No impact on alerts.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

## Policy Updates

| POLICY UPDATES                                                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Enhancements to Terraform GitHub and GitLab policies for Configuration Build Policies** | <p><strong>Changes</strong> - The policy name is being updated to reflect the latest changes.</p><p><strong>Current Policy Name</strong> - \* GitHub Actions Environment Secrets not Encrypted \* GitHub repository doesn’t have vulnerabilities alerts enabled \* Gitlab project commits are not signed \* Gitlab project does not prevent secrets \* Gitlab project has less than 2 approvals</p><p><strong>Impact</strong>- No impact on alerts.</p> |
| **New domain for Application Security Policy Reference Guide**                            | <p><strong>Changes</strong> - Starting from this release all policy documentation will be available on <a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference">Prisma Cloud Application Security Policy Reference</a>.</p><p><strong>Impact</strong>- No impact on alerts.</p>                                                                                                                                                     |
| **Azure Virtual Machine (Linux) does not authenticate using the SSH keys**                | <p><strong>Changes</strong> - The policy name is being updated to reflect the latest changes.</p><p><strong>Current Policy Name</strong> - Azure instance does not authenticate using the SSH keys</p><p><strong>Impact</strong>- No impact on alerts.</p>                                                                                                                                                                                              |
| **Policy Deletions**                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Docker GitHub repository is not private**                                               | <p><strong>Changes</strong> - This policy is deleted because the GitHub policies are modified in GitHub Policies.</p><p><strong>Impact</strong> - No impact on alerts.</p>                                                                                                                                                                                                                                                                              |

## IAM Policy Updates

The following IAM out-of-the-box (OOTB) policies are updated in Prisma Cloud:

<table data-header-hidden><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td>POLICY NAME</td><td>Current RQL</td><td>Updated RQL</td></tr><tr><td><strong>Azure VM instance associated managed identity with Azure built-in roles of Contributor/Owner permissions</strong></td><td><p><strong>Changes—</strong> The policy name will be updated.</p><p><strong>Current Name—</strong> Azure VM instance associated managed identity with Azure built-in roles of Contributor/Owner permissions</p><p><strong>Updated Name—</strong> Azure VM instance associated managed identity with Azure built-in roles of Owner permissions</p></td><td>NA</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; CodeBuild permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codebuild:CreateProject', 'codebuild:StartBuild', 'codebuild:StartBuildBatch') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codebuild:CreateProject', 'codebuild:StartBuild', 'codebuild:StartBuildBatch') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; CodeStar project permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codestar:CreateProject' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codestar:CreateProject' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Data Pipeline permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'datapipeline:ActivatePipeline', 'datapipeline:CreatePipeline', 'datapipeline:PutPipelineDefinition') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'datapipeline:ActivatePipeline', 'datapipeline:CreatePipeline', 'datapipeline:PutPipelineDefinition') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; EC2 permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'ec2:RunInstances' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'ec2:RunInstances' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Glue create job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Glue development endpoint permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateDevEndpoint', 'glue:GetDevEndpoint') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateDevEndpoint', 'glue:GetDevEndpoint') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Glue update job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:UpdateJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:UpdateJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Lambda create &#x26; invoke Function permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:InvokeFunction', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:InvokeFunction', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Lambda create Function &#x26; Event source mapping permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:CreateEventSourceMapping', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:CreateEventSourceMapping', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Lambda create Function &#x26; add permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:AddPermission', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:AddPermission', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; SageMaker create processing job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateProcessingJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateProcessingJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; SageMaker create training job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateTrainingJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateTrainingJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist and source.cloud.resource.id DOES NOT END WITH ':root'
</code></pre></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK                                                                                                               | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ---------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for MITRE ATT\&CK Cloud IaaS v13 & v14</strong></p><p><mark style="background-color:orange;">23.12.1</mark></p> | <p>Prisma Cloud now supports the MITRE ATT\&CK Cloud IaaS v13 & v14 compliance standard. This framework includes Att\&ck Tactics, Techniques and sub-techniques that attackers can leverage to compromise cloud applications and infrastructure.</p><p>You can now view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p> |

## Changes in Existing Behavior

| FEATURE                                                                                                                                                                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Checkov update for SCA Security scanning</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">23.12.1</mark></p> | Ensure Checkov or Bridgecrew CLI is updated to version 2.2.234 or later. Support for earlier versions is no longer supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Checkov CLI upgrade</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;">23.12.1</mark></p>                      | <p>The Checkov CLI has been upgraded to Checkov 3.0. The upgrade impacts a few known changes:</p><ul><li><strong>Level Up</strong>: This capability has been removed. This change is non-disruptive and affects only Bridgecrew standalone sign ups.</li><li><strong>Multi-Signatures</strong>: Multi-signatures in Python checks are being removed. This will only impact custom Python policies using this method.</li><li><strong>Deprecating flags for Suppression and Fix</strong>: CLI command of <code>--skip-fixes</code> and <code>--skip-suppressions</code> are being deprecated. Instead <code>--skip-download</code> is a recommended command.</li><li><strong>API Key Restriction and Repo-ID Parameter</strong>: Scans with API keys will now require the --repo-id parameter for repository scans allowing for easier platform mapping.</li><li><strong>Enhanced Argument Handling</strong>: The way to specify frameworks and skip frameworks will align to other flags where multiple values can be listed (like --check). For example: <code>--framework terraform,arm</code>..</li><li><strong>Pyston Docker Build Deprecation</strong>: The Pyston Docker build has been depreciated due to increasing complexities in support. The regular Checkov image will still be available for use.</li></ul> |

## REST API Updates

| CHANGE                                                                                                              | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Compliance Posture APIs</strong></p><p><mark style="background-color:orange;">23.12.1</mark></p>         | <p>The following new endpoints are available for the Compliance Posture API:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-v-2/">get /v2/compliance/posture</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-v-2/">post /v2/compliance/posture</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-trend-v-2/">get /v2/compliance/posture/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-v-2/">post /compliance/posture/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-trend-for-standard-v-2/">get /v2/compliance/posture/trend/{complianceId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-for-standard-v-2/">post /v2/compliance/posture/trend/{complianceId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-trend-for-requirement-v-2/">get /v2/compliance/posture/trend/{complianceId}/{requirementId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-trend-for-requirement-v-2/">post /v2/compliance/posture/trend/{complianceId}/{requirementId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-for-standard-v-2/">get /v2/compliance/posture/{complianceId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-for-standard-v-2/">post /v2/compliance/posture/{complianceId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-compliance-posture-for-requirement-v-2/">get /v2/compliance/posture/{complianceId}/{requirementId}</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-compliance-posture-for-requirement-v-2/">post /v2/compliance/posture/{complianceId}/{requirementId}</a></li></ul> |
| <p><strong>Asset Explorer and Reports APIs</strong></p><p><mark style="background-color:orange;">23.12.1</mark></p> | <p>The following new endpoints are available for the Asset Explorer and Reports API:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/save-report-v-2/">post /v2/report</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/get-resource-scan-info-v-2/">get /v2/resource/scan\_info</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-resource-scan-info-v-2/">post /v2/resource/scan\_info</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Asset Inventory APIs</strong></p><p><mark style="background-color:orange;">23.12.1</mark></p>            | <p>The following new endpoints are available for the AAsset Inventory APIs:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/asset-inventory-v-3/">get /v3/inventory</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-method-for-asset-inventory-v-3/">post /v3/inventory</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/asset-inventory-trend-v-3/">get /v3/inventory/trend</a></li><li><a href="https://pan.dev/prisma-cloud/api/cspm/post-method-asset-inventory-trend-v-3/">post /v3/inventory/trend</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

## Deprecation Notices

| **Deprecate the `aggregated` and `rest` fields**        | The `aggregated` and `rest` macros from the webhook custom JSON alerts are being deprecated and replaced by `AggregatedAlerts` and `Dropped` macros respectively. |
| ------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Deprecate `AccountID` macro from the Alerts payload** | The `AccountID` macro in the Alerts payload is deprecated and replaced by the `AccountIDs` macro.                                                                 |

## End of Support Notifications

| **Support for Cloud Native Network Segmentation (CNNS)** | The ability to create CNNS policies that Defenders use to limit traffic from containers and hosts is being removed. The configuration settings on the console (**Runtime Security > Defend > CNNS**) and the corresponding APIs for CNNS will be removed in `v32.00`. Radar has a container and a host view, where you can view the network topology for your containerized apps and hosts respectively, and this will continue to be available. |
| -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2023/features-introduced-in-december-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
