Releases: Nikolasel/nuclei-security-center
Release list
v0.4.7-beta — UI style guide and redesigned notification mails
Patch release on v0.4.6-beta. No schema changes — no new migrations.
Highlights
- A written UI style guide, and every screen moved onto shared primitives. New
docs/UI_STYLE_GUIDE.mddefines color roles, the type scale, spacing, page anatomy and rules for buttons, tables, row actions, forms, dialogs, confirmations and feedback. Pages now compose the shared components inweb/src/components/ui.tsx(Page/PageHeader,Table,RowActions,Alert,Badge,useConfirm, …), so buttons, headers, tables and messages look and behave the same everywhere (#339). - Redesigned scan notification mails. The digest and failed-scan mails are now embedded HTML templates styled to match the web app: brand header with the Nuclei logo (carried inline as a CID attachment), the app's system UI font stack, severity-colored counts table, status/severity chips and a clear "Open scan" button. Plain-text alternatives are unchanged (#340).
- Dependency updates. npm minor/patch bumps for
@tanstack/react-query,lucide-reactandvite(#341).
Merged
- #339 Add a UI style guide and align the web app with it
- #340 Design the scan notification mails: embedded HTML templates per the UI style guide
- #341 chore(deps): bump the npm-minor-patch group in /web
Full changelog: v0.4.6-beta...v0.4.7-beta
v0.4.6-beta — scan email notifications, schedule timezones, and admin environment view
Patch release on v0.4.5-beta. Adds migrations 0004_schedule_timezone.sql and 0005_scan_notification_outbox.sql, applied automatically at startup. Alpha databases remain rejected (they are not upgradeable).
Highlights
- Scan notification mail, opt-in per policy. A completed scan can email only its deltas — New / Changed (resurfaced) / Fixed, counted by effective severity, with links back to the scan and each finding — and failed or orphaned scans get a failure alert. Mail is off by default and switched on per scan policy (
notify_enabled), which can also set its own recipients and a minimum severity (e.g.lowdropsinfofrom counts and the list;unknownis kept). Without policy recipients, mail falls back to the deploymentSMTP_TOadmin mailbox.SMTP_HOST+SMTP_FROMenable sending;SMTP_PASSWORD_FILEis re-read before each send. An at-most-once outbox row is claimed before SMTP so a restart never resends; send failures are logged and never change a scan's terminal state (#321, #335, #328). - Schedules choose their own timezone. A schedule now stores an IANA timezone (default
UTC) alongside its cron expression, so0 3 * * *means 03:00 in that zone, including DST. Existing schedules keep UTC, and legacyTZ=/CRON_TZ=prefixes are migrated into the new column and stripped (#329, #332). - Settings → Environment configuration. Admins get a read-only view of the running backend's effective environment: every allowlisted variable with set/unset, the parsed value it actually consumes (booleans, durations, a credential-free
DATABASE_URL), and the built-in default. Secrets never leave the backend,SCAN_ZONESreports a seed-node count only, and each row carries the same description as the configuration docs — enforced by a drift test (#336, #337). - The findings list remembers your filters and sort. Filter and sort state persists per browser (#333).
- Template sync history collapses no-change runs. Repeated "no changes" sync results are summarized instead of filling the history (#334).
Merged
- #328 Email scan result changes and failures, opt-in per policy
- #332 Schedules: select an IANA timezone for cron
- #333 Persist findings filter and sort in localStorage
- #334 Summarize no-change template catalog syncs
- #337 Admin settings: show effective environment configuration
Full changelog: v0.4.5-beta...v0.4.6-beta
v0.4.5-beta — findings triage: result identity, richer filters, occurrence history
Patch release on v0.4.4-beta. Adds migration 0003_finding_result_identity.sql, applied automatically at startup; existing rows are backfilled from the preserved raw findings. Alpha databases remain rejected (they are not upgradeable).
Highlights
- The findings list now identifies each result.
GET /api/findingsalready returnedmatched_at,type,tagsandtarget_ids; the table now renders an Endpoint column by default (host + path, protocol pill) sohttps://host/adminandhttps://host/apiare distinguishable at a glance instead of collapsing into one host. Target, Tags, CVE, First seen, Matched at and Result identity are available from the Columns menu, which persists per browser. Columns resize from the header (keyboard-operable separators, double-click resets one, and the last visible column absorbs leftover width), andmatched_at/typeare filterable in both the structured filter and the legacy flat params (#313, #322). - Result identity is stored, not just inside the raw JSON. Nuclei's
matcher-name,extractor-nameandextracted-resultsbecome real columns onfindingsandfinding_lifecycle(migration 0003), written at ingest and backfilled for existing rows fromfindings.raw. Two lifecycle findings that share a template andmatched_atno longer render identically: the identity appears as a compact line under the name, with an opt-in Result identity column when you want to sort it or widen it to read a long value.matcherandextracted_resultare filterable, JSON/CSV/SARIF exports carry the fields, and the hashed dedup identity is unchanged (#315, #324). - The filter engine can ask real triage questions. Date ranges (
before/after/between, inclusive, date-only values accepted) on first- and last-seen;not_contains/is_empty/is_not_emptyfor name; server-sidesort+orderover an allowlisted field set with stable paging. The list and the export share one parser, so a download matches what is on screen (#311, #325). - Triage overlay state is queryable. Filter on
recast_severity(including recast vs never recast),observed_severityindependently of a recast,accept_expires_atranges,times_mitigated,occurrence_countandauto_mitigation_eligible. Accepted rows show their expiry in the list, and an Expiring acceptances quick filter returns accepted findings whose expiry falls in the next seven days — the ones that reopen silently otherwise (#312, #326). - Finding detail lists the retained occurrences. New
GET /api/findings/{id}/occurrences(viewer role, paginatedlimit/offset, newest first,404for an unknown finding) backs a section on the finding page with links to each occurrence, its scan and its target, plus a one-click jump to the latest. A finding that still exists always has at least one occurrence: deleting a scan drops its occurrences andoccurrence_counttogether, and deleting every scan that observed a finding deletes the lifecycle row, so the list never implies history it cannot show (#314, #327).
Fixes
- Long extracted results wrap instead of overflowing their container on the occurrence and finding detail pages (#317).
Development environment
- The local S3 stand-in is Garage (
dxflrs/garage) rather than MinIO, which no longer publishes an anonymously pullable image. Compose, the deployment docs and the troubleshooting guide were updated; the backend'sObjectStoreand its environment configuration are unchanged, and any S3-compatible endpoint still works (#320).
Maintenance
- Frontend dependency bump (npm minor/patch group) via dependabot (#323).
Merged
- #317 fix(ui): wrap long extracted results on occurrence and finding detail pages
- #318 Show the running backend version in the account menu
- #320 Replace local MinIO with Garage for raw-output archival
- #322 Show matched URL, type, tags, and target on the findings list
- #323 chore(deps): bump the npm-minor-patch group in /web with 2 updates
- #324 Surface Nuclei matcher and extracted results on findings
- #325 Findings filters: date ranges, name negation, and sorting
- #326 Findings filters: triage overlay state
- #327 List retained occurrences on finding detail
Full changelog: v0.4.4-beta...v0.4.5-beta
v0.4.4-beta — OIDC host canonicalization, light/dark theme, and operator UI fixes
Patch release on v0.4.3-beta. No schema changes.
Highlights
127.0.0.1no longer breaks login.GET /api/auth/loginand SPA document requests whose cookie host (hostname + non-default port) does not matchAPP_BASE_URLare302'd to the same path on the configured origin before an auth-state cookie is minted, so a127.0.0.1visit cannot start a flow whose callback and host-locked cookies live onlocalhost— the "invalid or expired login state" failure (#298, #308). Scheme is ignored in the comparison, so a TLS-terminating ingress that presents the publicHostover plaintext cannot 302-loop. Redirect destinations are always derived fromAPP_BASE_URL, never fromHost, so a spoofed host is not an open redirect; a missing or malformedAPP_BASE_URLfails closed./healthzand other/api/*routes are not redirected, so probes and service-account callers may still use an IP.- Light/dark theme toggle in the header. Flips the
darkclass on<html>— now a class-based Tailwind variant — persists per browser, and follows the OS preference until the first toggle. Applied before first paint so the initial render does not flash the wrong theme,color-schemefollows so browser chrome matches, and astoragelistener keeps multiple open tabs in sync (#292, #293). - Scanner Nodes table fits 1280×800. Health and Discovery collapse into one Status column, tags and CIDRs move under Name/Scope, the nuclei version and last-seen fold into the catalog cell, and the action column is pinned with a scroll shadow — Edit / Sync / Delete stay on screen without horizontal scrolling (#299, #307).
Fixes
- Target Save requires Name and Hosts. Both fields are marked required (visible
*,aria-required) and Save stays disabled until they have values, matching backend validation and the node-create form (#300, #306). - Custom Templates empty state. The catalog table's filter-oriented copy ("No templates match these filters") is replaced with "No custom templates yet." on the Custom Templates tab, which has no filters (#301, #305).
Development environment
- Cloud Agent (Cursor) environment.
.cursor/environment.jsonplusinstall/start/dockerd/logsscripts bring up the docker-compose stack so cloud agents can verify PRs against the real stack..cursor/is deliberately not gitignored so that environment stays shared (#302). - Local AI-agent state is ignored.
.claude,.commandcode,.codex,.gemini,.qwen,.opencode,.crush,.continue,.windsurf,.roo,.kilocode,.junie,.specstory,.aider*can no longer be committed by accident; shared instructions stay inAGENTS.md(#303).CLAUDE.mdis now a one-line@AGENTS.mdimport rather than a symlink, so Cursor does not ingest a second copy (#291). - Compose MinIO image moved to Quay (
quay.io/minio/minio) — MinIO no longer publishes an anonymously pullable Docker Hub image, sodocker compose upwould have failed against Docker Hub. - Docs refreshed for the above:
API.md,ARCHITECTURE.md,DEVELOPMENT.md,README.md,CONTRIBUTING.md, and the admin guide (Authentication / Configuration / Deployment / Troubleshooting).
Maintenance
- Go toolchain → 1.26;
coreos/go-oidc/v33.21.0,jackc/pgx/v55.11.0,golang.org/x/oauth20.37.0,golang.org/x/time0.16.0. - Frontend: React / React DOM 19.3, Vite 8.3,
@tanstack/react-query5.103.1,lucide-react1.46,react-router-dom7.18.4,@vitejs/plugin-react6.1.1.
Merged
- #291 docs: load agent instructions once via CLAUDE.md
@AGENTS.md - #293 Add header light/dark theme toggle (#292)
- #294 chore(deps): bump
github.com/coreos/go-oidc/v3to 3.21.0 - #295 chore(deps): bump the npm-minor-patch group in /web with 4 updates
- #296 chore(deps): bump the go-minor-patch group
- #297 chore(deps): bump the npm-minor-patch group in /web with 5 updates
- #302 Add Cloud Agent development environment (Docker Compose stack)
- #303 chore(gitignore): ignore local AI agent state, keep
.cursortracked - #305 fix(ui): show a true empty state on Custom Templates (#301)
- #306 fix(ui): require Name and Hosts before saving a target (#300)
- #307 fix(ui): keep scanner-node row actions visible at 1280×800 (#299)
- #308 Redirect 127.0.0.1 onto APP_BASE_URL before OIDC login (#298)
- #309 chore(deps): bump the npm-minor-patch group in /web with 4 updates
Full changelog: v0.4.3-beta...v0.4.4-beta
v0.4.3-beta — Nuclei 3.11.1, operator UI fixes, and public-launch docs
Patch release on v0.4.2-beta. No schema changes.
Highlights
- Nuclei 3.11.1. Scanner image pin (
deploy/Dockerfile.scanner) so new scans run the current upstream binary. - Template-set Duplicate copies membership. Duplicating an exact or exclude set no longer saved an empty set (#277).
- Nodes page shows effective naabu scan type.
GET /v1/capabilitiesreports the node's normalizedNAABU_SCAN_TYPE(SYN default, connect fallback); the nodes table surfaces SYN / Connect / unknown without shelling in. A scan policy'sdiscovery_scan_typecan still override (#271). - Scan-policies table layout. Execution knobs (rate, concurrency, timeout, max-host-error, resp read/save) collapse into one summary column so the row fits at 1280px without clipping Delete (#276).
Public launch
- Canonical AGPL-3.0
LICENSE(GitHub now detects AGPL-3.0),CONTRIBUTING.md, Contributor Covenant 2.1, PR and bug-report templates. - GHCR backend/scanner images are public; admin docs cover pull coordinates and Compose wiring. Prerelease tags publish version +
sha-*only (nolatest). - Administration guide (
docs/admin/) is published to the GitHub wiki onmainandv*tags.
Maintenance
- Frontend minor/patch bumps:
@tanstack/react-query,lucide-react, Vite,@vitejs/plugin-react.
Merged
- #278 chore(scanner): upgrade pinned nuclei to v3.11.1
- #279 fix(template-sets): copy members and exclusions when duplicating a set (#277)
- #280 feat(nodes): surface effective naabu scan type on nodes page (#271)
- #281 fix(scan-policies): collapse execution knobs into summary column (#276)
- #284 chore: public-launch prep (license, fixtures, community files)
- #285 docs(release): correct stale comment — GHCR images are public
- #287 docs: publish pull instructions for the public GHCR images
- #288 docs(admin): publish administration guide to the GitHub wiki
- #289 fix(wiki): authenticate wiki checkout like the main repo
- #290 chore(deps): bump the npm-minor-patch group in /web with 5 updates
Full changelog: v0.4.2-beta...v0.4.3-beta
v0.4.2-beta — Bound nuclei response sizes and auto-tune GOMEMLIMIT to prevent OOM
Fixes the scanner OOM-killed at the container 2 GiB cap reported in #274.
Problem
During a scan of ~106 endpoints the nuclei process was killed twice by the kernel OOM killer (CONSTRAINT_MEMCG) after reaching the container's 2 GiB limit. Heap climbed from baseline to ~2 GiB within ~5 s — dozens of simultaneous connections to a single CDN edge with 1.5–4.7 MiB unread Recv-Q each, plus Go heap anon-rss:2 GiB. Model: heap ≈ 1–1.5 × concurrency × response-size-read (nuclei default 10 MiB) stacked with cgroup-accounted TCP buffers.
Fix (#275)
Two complementary, deployment-independent fixes:
-
Per-response caps as scan-policy knobs —
scan_policies.response_size_read/_save(nullable,>0,CHECK) via forward migration0002_add_scan_policy_response_limits.sql(post-beta freeze,0001_init.sqluntouched). Plumbedtypes.ScanOptions→store.ScanPolicy→validateScanPolicy/overlayScanPolicy→runner.buildArgs(-response-size-read/-save, omitted ⇒ nuclei default 10 MiB/1 MiB) → bundle snapshot → SPA (modal/table, placeholders10485760/1048576). Loweringreadtoward 1 MiB linearly shrinks worst-case heap. -
Automatic
GOMEMLIMITon the scanner node —internal/scanner/memlimit.goreads cgroup limit from/sys/fs/cgroup/memory.max(v2) thenmemory/memory.limit_in_bytes(v1) (treatingmax/>1 PiB/sentinel9223372036854771712as unlimited), derivesGOMEMLIMIT ≈75%of cap (truncated to MiB, floored at 64 MiB, documented assumption for non-tiny cgroups), leaves 25% for kernel TCP buffers/RSS slack. ExplicitGOMEMLIMITwins (runtime already honored at startup). Applied viaGOMEMLIMITenv (inherited bynuclei/naabu) anddebug.SetMemoryLimitso GC pressure replaces kills.
Tests: TestBuildArgsResponseSize, TestOverlayScanPolicy (response sizes), TestValidateScanPolicy, TestParseGOMEMLIMIT (TiB/MiB/GiB/KiB/B, case-insensitive), TestParseCgroupLimitValue, TestGomemlimitFromCgroup (floor/truncation).
Operational notes
- Existing
GOMEMLIMIT=1500MiBworkaround still honored (explicit wins). - Existing policies get nuclei defaults until edited; set
response_size_readto1048576(1 MiB) to bound CDN streaming. - No
tcp_rmemchange; headroom is inGOMEMLIMIT.
Merged
Full changelog: v0.4.1-beta...v0.4.2-beta
v0.4.1-beta — Fix scanner image HOME for cap_drop ALL
Fixes the scanner startup failure under least-privilege hardening (cap_drop: ALL) reported in #272.
Fix
- Scanner image (
deploy/Dockerfile.scanner): hardened/rootto0550but leftENV HOME=/root. WithCAP_DAC_OVERRIDEdropped,nuclei’smkdir $HOME/.configfailed withEACCES(mkdir /root/.config: permission denied) and every scan failed closed. Now bakes a dedicated privateHOMEat/home/scanner(mkdir -p /home/scanner && chmod 0700,ENV HOME=/home/scanner) fornuclei/naabu/uncoverconfig+cache ($HOME/.config,$HOME/.cache,$HOME/nuclei-templates). Avoids the world-writable/tmp(1777) symlink/pre-creation surface thatHOME=/tmpwould have kept. A future move to a non-rootUSERwill need a matchingchown(e.g.chown 1001:0 /home/scanner).
Operational notes
cap_drop: ALLis often paired withread_only: true. With a read-only root filesystem the scanner now needs writable scratch at both/home/scanner(imageHOME) and/tmp(SCANNER_WORK_DIRdefaults to a private0700dir underos.TempDir()//tmp). Mount writableemptyDir/tmpfs volumes at both paths (as withEXPORT_SPOOL_DIR/TEMPLATE_SYNC_DIRfor the backend). Documented indocs/ADMIN_GUIDE.md:103andSCANNER_WORK_DIR.
Verification
- Before:
docker run --cap-drop ALL ghcr.io/...:0.4.0-beta nuclei -tl→mkdir /root/.config: permission denied - After:
docker run --cap-drop ALL ghcr.io/...:0.4.1-beta nuclei -tl→Successfully installed nuclei-templates at /home/scanner/nuclei-templates ls -ld /home/scanner→drwx------(0700, root-owned),/rootstaysdr-xr-x---, scanner/v1/capabilitieshealthy undercap_drop ALL;--read-only --tmpfs /tmp --tmpfs /home/scannerstarts clean.
Merged
Full changelog: v0.4.0-beta...v0.4.1-beta
v0.4.0-beta — First beta: security-hardening pass, template-set modes, scan bundles
The first beta release. Nuclei Security Center graduates from alpha after a comprehensive external security review — the bulk of this release is a security-hardening pass across auth, sessions, scanner I/O, and resource bounds — plus new template-set modes, versioned scan bundles, a mobile-friendly SPA, and a frozen migration baseline that makes future schema changes forward-migratable.
Highlights
- Security-hardening pass (external review). A full external security review of the codebase drove a wide set of fixes: host-locked and CSRF-protected OIDC login and session cookies, bounded session TTL with an admin revocation path, per-subject live-session caps and paginated admin sessions, audited failed-authentication and OIDC-callback 401s, RP-initiated IdP logout that fails closed when server-side revocation fails, blocked scanner-client redirects, bounded scanner responses / stderr / JSONL records, bounded findings queries and exports, bounded scan-bundle and auth-flow creation, escaped
LIKEmetacharacters in filters, clickjacking/MIME security headers, aservice_accounts.roleCHECK constraint, rejected mTLS-on-HTTP misconfiguration, andS3_USE_SSLnow defaulting to true (fail closed). - Explicit template-set modes. Template sets are now
exact,all, orexclude, resolved at dispatch, replacing the retired POC filter columns. - Versioned scan bundles. Complete scans export and import as versioned bundles (JSON or zip), with streamed decoding bounded to a fixed heap and imported coverage as an explicit opt-in.
- Host discovery independent of scan type. Naabu host discovery is decoupled from SYN/connect selection, and executed nuclei/naabu commands are now captured in the scan execution log.
- Mobile-friendly SPA. The React interface is usable on small/mobile viewports, with a sidebar that stays visible while scrolling.
- Reliability. Reliable scan cancellation (#217), scanner work-dir/job reclamation after completion, ascending-order lifecycle locking to avoid deadlocks across concurrent scan deletions, and overflow-safe retention windows.
Beta readiness — migration baseline frozen
- The alpha migration chain is squashed into a single consolidated baseline (
0001_init.sql), now frozen as of this release. From beta onward, each schema change ships as a new numbered forward migration that applies on an existing database; applied migrations are immutable and checksum-verified at startup. - Alpha databases are not upgradeable to beta. Deploy beta against an empty Postgres database and move portable data with template/template-set exports and scan bundles; the backend rejects an unsupported migration history at startup instead of attempting a partial upgrade.
Upgrade notes
- Start from an empty PostgreSQL database. There is no in-place upgrade path from any alpha.
S3_USE_SSLnow defaults totrue. Set it explicitly tofalseonly for a plaintext dev endpoint.
Maintenance
- Dependency updates across Go modules, frontend npm packages, the Go toolchain (1.27), and base images.
Full changelog: v0.3.0-alpha...v0.4.0-beta
v0.3.0-alpha
This alpha release makes scan policies the central configuration for every scan, adds optional naabu-based port discovery, and expands operational visibility and findings triage.
Highlights
- Policy-driven scans: every scan and schedule now selects a reusable scan policy that combines an approved target, an optional template set, and Nuclei execution controls. Policies add
max_host_errorsupport and keep scans in scope by construction. - Port discovery before Nuclei: policies can run a naabu pre-pass so Nuclei scans only discovered
host:portendpoints. Discovery is enabled by default, supports SYN and connect modes, has independent timeout/rate/probe/retry tuning, reports live discovery progress, and persists the endpoints that were scanned. Discovery failures fail closed. - Expressive findings search: the findings view now has a ServiceNow-style condition builder with AND/OR groups, field-specific operators, breadcrumbs, and an open-findings default. The same structured filter applies consistently to JSON, CSV, SARIF, and raw exports.
- Better scan operations: completed scans can archive and download the scanner execution log; scan detail records the selected scanner node and shows a live ETA; polling budgets now derive from the policy's discovery and scan timeouts.
- Configurable retention: admins can automatically remove old terminal scans while preserving the latest scan needed for lifecycle calculations, with configurable treatment of ad-hoc scans and audit events for sweeper deletions.
- Refreshed interface: adds the neon Nuclei Security Center logo, favicon, and updated product branding.
- Maintenance: updates Go/Node GitHub Actions and frontend dependencies, and consolidates contributor-agent guidance.
Breaking changes
POST /api/scansnow accepts only{ "scan_policy_id": "..." }; the former target, template-set, raw-spec, and timeout launch inputs are removed.- Schedules now reference a scan policy instead of carrying target/template/timeout configuration. Migration
0017clears pre-alpha schedules created under the old schema. - Port discovery defaults to enabled for new policies. Operators can disable it per policy when a scanner environment should run Nuclei directly.
Merged changes
- #115 naabu port-discovery pre-pass before Nuclei
- #119 neon product branding
- #114 findings condition builder
- #113 scan policies as central scan configuration
- #110 scanner execution-log archival and download
- #112 selected scanner node and live ETA
- #111 configurable scan retention
- #105, #106 dependency updates
Full changelog: v0.2.0-alpha...v0.3.0-alpha
v0.2.0-alpha — Scanner node fleet, per-node mTLS, hardened multi-arch images
Alpha milestone focused on running scans across a fleet of scanner nodes, hardening the
backend↔node trust boundary, and shipping minimal, multi-arch container images. Also brings
service-account tokens, live scan progress, and a reorganized web UI.
Pre-release / alpha: interfaces and schema may still change between alpha tags.
Highlights
Scanner node fleet
- DB-backed scanner node registry — admin-managed nodes (config-seeded on first boot), replacing the static single-node config. (#22)
- Scan zones — map each node to the network CIDRs it serves; dispatch picks the node whose zone contains the target, with overlapping CIDRs rejected. (#77)
- Node health monitoring — the backend polls each node's
/v1/capabilities; dispatch fails fast to a known-unhealthy node instead of hanging. (#98) - Scanner nodes admin UI — manage nodes and see health/last-error from the web app. (#99)
Backend ↔ node security
- Per-node mTLS — each node can carry its own server-CA + client cert/key (client key write-only), so nodes in untrusted segments only accept dispatch over a mutually-authenticated connection, bearer token still on top. (#26)
Container images & deployment
- Red Hat UBI 10 Micro base for both backend and scanner — minimal, no package manager/shell, long support window. (#103)
- Multi-arch
linux/amd64+linux/arm64manifest lists (Graviton / Apple-silicon runners run without a second image). - Self-contained scanner — a pinned, SHA-256-verified
nucleibinary plus the community templates baked in at build time, refreshed to the newest set before each scan. No dependence on a mutable upstreamnuclei:latesttag. - Backend now runs non-root; both images ship a CA bundle for outbound TLS.
Scan control & visibility
- Live scan progress bar driven by nuclei's
-stats-json(percent / requests / hosts / rps), including multi-target scans. (#66) - Stop/cancel + delete scans, with target visibility on the scan views. (#74)
- Partial results are ingested before a failure is recorded, and
nuclei_version/templates_commitare captured even on failed or cancelled scans. (#89) timeout_secoverride honored for schedules, not just ad-hoc scans.
Access & resilience
- Service-account API tokens for headless/automation access, with an admin UI to create/rotate/revoke. Audit events distinguish
service_accountfromuseractors. (#70) - Ambient/IAM object-store credentials — the backend can use an instance/role identity for S3 instead of static keys. (#72)
- Rotating database credentials via a password file re-read per connection. (#71)
- Infrastructure faults (unreachable session/identity store) now surface as 503, no longer masked as
401. (#82)
Web UI
- Collapsible, category-grouped sidebar navigation (Findings / Scanning / Admin) with an icon rail and tooltips. (#96)
- Modal scrolling fix for tall content and wider content on large screens.
Findings
- Findings read path refactored behind a
FindingsSearcherinterface (seam for richer multi-value filtering). (#92) - Lifecycle history is repaired when a scan is deleted, and evidence-free rows are dropped rather than left "active".
Images
Published to GHCR as multi-arch manifest lists:
ghcr.io/nikolasel/nuclei-security-center-backend:0.2.0-alphaghcr.io/nikolasel/nuclei-security-center-scanner:0.2.0-alpha
Full changelog: v0.1.2-alpha...v0.2.0-alpha