March 2025 Monthly Release

For help upgrading to the latest version, contact your Cloudhouse Representative. The following table describes each component available to upgrade within this release of Cloudhouse Guardian (Guardian).

Tip: For more information on the known issues currently present within Guardian, see Known Issues .

Release Date Guardian Platform Guardian Web Linux Agent
19th March 2025 V4 V3.53.0 V5.41.0

Guardian Web Application V3.53.0

Here's what's included in V3.53.0 of the Guardian web application as part of the March 2025 monthly release.

New Features

There are no new features included within this release of the Guardian web application.

Other Enhancements

The following enhancements are included within this release of the Guardian web application.

Node Scan Results Field Change

On the Node Scan Results page, within the Compare to section, the Previous Scan drop-down list name has been updated. It is now displayed as Another Scan. All other functionality remains the same. Select an option from the drop-down list to generate a difference report for two scans within the node scan results page. For more information on this type configuration differencing, see Scan Differencing.

Improved Benchmark Task Efficiency and Run Times

Previously, any script files included within a benchmark job run were being automatically stored within the database record, resulting in higher storage and payload. We have now changed this behavior, allowing for any script records to be retrieved upon request instead, reducing the payload significantly.

Tip: We have also reconfigured benchmark processing jobs to improve benchmark run times.

New AWS IAM Node Types: Groups, Policies, Roles, Users

We have added support for AWS IAM nodes by introducing the following additional AWS IAM node types to Guardian: AWS IAM Role, AWS IAM Policy, AWS IAM User, and AWS IAM Group. This enhancement allows you to more easily distinguish between different IAM resource types within the Guardian UI. For more information on how to add these node types, see Amazon Web Services (AWS) Node.

On the Edit AWS Integration Settings page, the following options have also been added to the list of detectable elements:

  • IAM Groups

  • IAM Policies

  • IAM Roles

  • IAM Users.

For more information, see AWS Integration.

Additionally, when a new IAM group, policy, role, or user node is added to Guardian, a dynamic node group is automatically created for that node type within the Monitored tab (Inventory > Monitored). For more information, see Static / Dynamic Node Groups.

Improvements to CloudFormation Nodes with Templates

When viewing the Node Scan Results for a CloudFormation node, if there are any templates contained within the scan results, you can now view them as a raw text file by clicking the View Raw File button. Previously, the templates were displayed as attributes on the node's scanned configuration item(s).

Fixed Issues

The following issues have been fixed in this release of the Guardian web application.

GWB-5525 – Inconsistent Behavior When Deleting Integrations

On the Integrations tab (Control > Integrations), attempting to delete an integration via one of the following methods was resulting in inconsistent confirmation messages and deletions:

  • Clicking the Ellipses () button for an existing integration, then selecting Delete.

  • Selecting the checkbox for an existing integration, then selecting Delete.

This issue has been fixed in V3.53.0 of the Guardian web application. Now, when deleting an integration via any method, a confirmation message is displayed and the integration is deleted as expected.

GWB-6127 – Adding Valid Regular Expressions to Node Group's Settings (Node Rules) Resulting in Error

If the optional Monitored skin was enabled, adding valid regular expressions to a new or existing node group's settings (node rules) was incorrectly resulting in an error. This issue was the result of a misalignment in validation criteria between JavaScript and Ruby. We have now fixed the validation criteria so that any regular expressions run by Ruby are being validated against the same criteria as JavaScript. Now, you can add node rules to a new or existing node group's settings, regardless of whether the optional Monitored skin is enabled or disabled. For more information, see Node Rules.

Note: To enable the optional Monitored skin, contact your Cloudhouse Representative.

GWB-6161 – Exception Thrown Running Single Check Benchmarks

When running single check benchmarks, adding additional checks to the benchmark was causing the job run to fail and duplicate error messages to be displayed. This issue was caused by an exception being thrown after the first request. This issue has now been fixed within the source code, allowing additional checks to be added to single check benchmarks without issue.

GWB-6164 – ServiceNow Node Synchronization Events Failing

In V3.52.1 of Guardian, running a ServiceNow node synchronization job was sometimes resulting in the following error, 'Validation failed: Framework can't be blank, Agent can't be blank, Library can't be blank'. The issue was caused by an existing Agent node being detected by the synchronization job; Guardian was incorrectly attempting to re-add the node but failing halfway due to various parameters. The issue has been fixed by conditioning Guardian to not attempt to re-add any duplicate nodes that are detected during a node synchronization event. Now, you can re-synchronize ServiceNow nodes as expected in this version of Guardian.

GWB-6167 – Latest Version of Benchmark Checks not Displayed

When adding a benchmark to a node group, the benchmark was not displaying individual checks or the version number of the benchmark. This issue has now been fixed and when adding a benchmark to a node group, the version of the benchmark, as well as the individual checks are now displayed as expected.

GWB-6168 – API Benchmark Report Parameters Review

We have updated the CSV and JSON API endpoint parameters so that the results being returned are consistent across each instance of the API.

Linux Agent V5.41.0

Here's what's included in V5.41.0 of the Linux Agent as part of the March 2025 monthly release.

New Features

There are no new features included within this release of the Linux Agent.

Other Enhancements

The following enhancements are included within this release of the Linux Agent.

New AWS IAM Node Types: Groups, Policies, Roles, Users

Support for new AWS IAM node types are now available, see New AWS IAM Node Types: Groups, Policies, Roles, Users above for more information.

Improvements to CloudFormation Nodes with Templates

You can now view templates in raw text format from the Node Scan Results page, see Improvements to CloudFormation Nodes with Templates above for more information.

Fixed Issues

No issues have been fixed in V5.41.0 of the Linux Agent.