This release includes the following enhancements: Release date: May 13, 2025 AI AssistantA new AI Assistant is available in dotTEST. Users can ask questions about the product in natural language and the AI Assistant will answer based on documentation and integration with a pre-configured LLM provider. New and existing users can learn the product and get help more efficiently using the AI Assistant. Access the AI Assistant by navigating in the desktop to Parasoft > Show View > AI Assistant. See The AI Assistant for more information. Code Coverage Enhancements
Static Analysis Enhancements
Support for .NET 9Support for .NET 9 has been added. See Supported Frameworks. Support for C# 13dotTEST can now analyze code written in C# 13. Test Impact Analysis EnhancementsTest impact analysis now supports re-executing tests that failed in the base run along with affected tests. See dottest.tia.run_failed_tests.
|
Rule ID | Updates |
|---|---|
| CS.TRS.LOCKSETGET | C#13 syntax support. |
| SPR.HARDCONN | New parameters have been added. Issues have been fixed. |
The following rules have been updated:
Rule ID | Updates |
|---|---|
| BD.PB.CC | Improved consistency of results. |
| BD.SECURITY.TD | The rule has been significantly updated to improve performance and accuracy. |
The following platform is now supported:
<rule-id>-<severity> pattern (e.g., BD.PB.VOVR-3) used in a suppression comment or suppression record is now taken into account when suppressing violations. A violation is suppressed if its severity matches or is lower than the one specified in the suppression pattern. If the rule's severity has increased, existing suppressions will no longer apply.Support for the following OS is now deprecated:
Bug/FR ID | Description |
|---|---|
| DT-18943 | Occurring popup |
| DT-22842 | Section of viewing reports and UT with passed, failed, incomplete |
| FA-6806 | BD.SECURITY.TDFNAMES false positive caused by incorrect propagation of tainted data |
| FA-10104 | Inconsistent results for BD.PB.CC |
| FA-10244 | BD.PB.VOVR false positive on variable updated in a loop, which is traversed only once |
Bug/FR ID | Description |
|---|---|
CVE-2026-22732 | Critical vulnerability resolved by updating to spring-security version 6.5.9 |
CVE-2026-29145 | Critical vulnerability resolved by updating to Tomcat version 10.1.53 |
CVE-2026-33937 | Critical vulnerability resolved by updating to handlebars version 4.7.9 |
Bug/FR ID | Description |
|---|---|
| CVE-2025-7783 | Critical vulnerability resolved by upgrading form-data to 4.0.6. |
| CVE-2026-27601 | Critical vulnerability resolved by upgrading underscore to 1.13.8 |
| CVE-2026-41842 | Critical vulnerability resolved by upgrading Spring to 6.2.19 |
| CVE-2026-43515 | Critical vulnerability resolved by upgrading Tomcat to 10.1.56 |
| CVE-2026-46681 | Critical vulnerability resolved by upgrading nevware21/ts-utils to 0.14.0. |
| CVE-2026-47838 | Critical vulnerability resolved by upgrading Spring Security to 6.5.11 |
| CVE-2025-48734 | Critical vulnerability resolved by upgrading commons-beanutils to 1.11.0 |
| CVE-2025-48976 | Critical vulnerability resolved by upgrading commons-fileupload2-core to 2.0.0-M4 |
CVE-2026-54512 CVE-2026-54513 | Critical vulnerability resolved by upgrading Jackson to 2.18.8 |
Bug/FR ID | Description |
|---|---|
CVE-2026-55276 CVE-2026-53434 CVE-2026-59083 CVE-2026-59084 | Critical vulnerability resolved by upgrading Tomcat to 10.1.57 |
| CVE-2026-53914 | Critical vulnerability resolved by upgrading kotlin-stdlib to 2.4.20 |
Bug/FR ID | Description |
|---|---|
| CVE-2026-8763 | Critical vulnerability resolved by upgrading bc-fips to 2.1.3 |
| CVE-2026-58062 | Critical vulnerability resolved by upgrading bc-fips to 2.1.3 |
| CVE-2026-59638 | Critical vulnerability resolved by upgrading bctls-fips to 2.1.24 |
For information about this release, see https://docs.parasoft.com/display/DOTTEST20251/Updates+in+2025.1. |