Skip to content

Ghostwriter v6.3.2

Choose a tag to compare

@chrismaddalena chrismaddalena released this 21 Apr 21:30
· 639 commits to master since this release
a328fd2

Summary

This release primarily makes changes to the BloodHound integration to address some edge cases and clarify permission boundaries.

CHANGELOG

[6.3.2] - 21 April 2026

Changed

  • The BloodHound global server configuration now has an explicit flag to be set that allows it to be used as a fallback for projects
    • Defaults to off so the configuration is more explicitly opt-in
    • Previously, the fallback was implicit when you configured the global server
  • Adjusted permissions for triggering a global BloodHound data fetch
    • Changed from any authenticated user to users with access to a project using the global configuration or privileged users
  • Changed some Cypher queries to use count() to avoid potential issues with very large environments
  • Pinned base images for containers to specific versions for reliability (e.g., node:25 to node:25.9.0)
  • Adjusted the collection of users with pwdlastset older than 90 days to only include enabled users

Fixed

  • Fixed the BloodHound API fields being required when trying to create a project via the GraphQL API (Fixes #877)