Ghostwriter v6.3.0-rc2
Pre-releaseSummary
We've made the upcoming v6.3.0 even better with a significant redesign of the activity logging experience. We've also made other improvements based on user feedback.
CHANGLEOG
[6.3.0-rc2] - 25 March 2026
Added
-
Passive Voice Detection: Added support for performing passive voice identification inside the collaborative editor
- Ghostwriter now hosts a small local copy of the spaCy language model for text analysis
- Select "Check Passive Voice" in the collaborative editor to examine text and highlight instances of passive voice
- See the wiki for more details and an explanation for how to change the model's language
-
Operation Log Evidence Linking: Added support for linking evidence to individual operation log entries (Closes #132)
- New
OplogEntryEvidencemodel to create many-to-many relationships between log entries and evidence - New GraphQL
linkOplogEvidenceaction to attach evidence via API - New web form (
OplogEvidenceCreateview) to attach evidence through the UI - Evidence appears in a dedicated section within each log entry, with friendly names and direct links to the original evidence
- Automatic "evidence" tag applied when evidence is linked to an entry
- New
-
Operation Log Terminal Recordings: Added support for uploading and playback of Asciinema terminal session recordings (.cast and .cast.gz files)
- New
OplogEntryRecordingmodel to store a single terminal recording per log entry - New GraphQL
uploadOplogRecordingaction for base64-encoded file uploads via API - New GraphQL
downloadOplogRecordingaction to retrieve recordings and metadata - New Django views for recording upload, deletion, and download with file serving and inline playback support
- Support for Asciinema player integration for viewing recordings directly in the log entry's details pane
- Automatic "recording" tag applied when a recording is uploaded
- New
-
Automatic Tag Management for Log Entry Features: Evidence linking and terminal recordings automatically apply and remove tags
evidencetag added when first evidence is linked, removed when the last evidence is unlinkedrecordingtag added when a recording is uploaded, removed when the recording is deleted- Tags can be used for filtering log entries and visual identification
Changed
-
Ghostwriter CLI v1.0.0: Updated the pre-built Ghostwriter CLI binaries to v1.0.0
- Review the Ghostwriter CLI CHANGELOG for complete notes
- Going forward, we recommend all users use the new published container images for easier updates
- Existing installations will need to migrate some files
- Copy the ssl/ directory to the ghostwriter/ directory inside your operating system's data file directory
- Also copy any custom settings files from config/settings/production.d to ghostwriter/settings/
- Ghostwriter CLI can be used with
--mode local-prodto keep the old behavior of using a local copy of Ghostwriter's code- You will need to do this if you are using a customized version of the codebase
-
New User Interface for Operation Logs: Replaced the table view for operation logs with two pane interface (Closes #831)
- New interface is similar to those used by many email clients
- Log entries appear on the left-side with at-a-glance information
- Details appear on the right-side in a details pane
- Details pane includes dedicated sections for attaching evidence and uploading terminal recordings
-
Text Evidence Previews: Text evidence now has previews in the collaborative editor like image evidence
-
Pasting Images into Collab Editor: You can now paste an image file or screenshot in your clipboard into a collaborative editor field
- The paste will automatically trigger the modal window for uploading your evidence
- Your filename will be the default friendly name for the upload
Security
- As we allow more user-editable content to be rendered in the DOM, we have implemented stronger controls to prevent JavaScript injection
- Updated the allowed HTML attributes to be more targeted
- Added sanitization to activity log entries that support rich text (
commentsanddescription) - Added
DOMPurifyto the project for an extra layer of security and client-side sanitization