Skip to content

Version 3.260731.0

Choose a tag to compare

@Filigran-Automation Filigran-Automation released this 31 Jul 08:50
9d83b40

Enhancements:

  • #6983 feat(reporting): full-fledged reporting module and platform enhancements
  • #6952 feat(platform): recurring atomic testing, filter negation, channel redesign, clean bootstrap and UX consistency wave
  • #6938 feat(catalog): display the catalog connector container version on the integration detail page
  • #6848 feat(platform): restore simulation execution and batch overview, lessons and catalog fixes
  • #6808 feat: continue platform deep UX improvements and add expectation security platform foundation
  • #6734 [XTMHub]🎯 Connect to Hub from OpenAEV Design
  • #6470 [Multi-Tenancy] - Enhance the tenant switcher
  • #6399 feat(multitenancy): API isolation v2 collector GCatalog
  • #6284 [Multi-Tenancy] Share Instance name ( tenant name ) with openCTI for security coverage results.
  • #6164 US.6-T.1 -> [Audit Logging Token lifecycle audit logging
  • #5793 US.8 -> Critical Log Write Failure — Stack Halt
  • #5705 US.6 -> [Audit Logging][SessionId] Expired session event
  • #5484 US.3-T.1 -> [Audit Logging][Transport Abstraction] Create AuditTransport interface + AuditTransportDispatcher + LogAppenderTransport
  • #5483 US.1-T.4 -> [Audit Logging][Collection: Auth] Login/logout/SSO auth event hooks + tests
  • #5480 US.1-T.1 -> [Audit Logging][Collection: CRUD] Core AOP aspect + AuditLogService refactoring
  • #3496 fix: payload not loading and inject stuck in pending after Docker deployment on new instance

Bug Fixes:

  • #7063 fix(api): injector-registered security platforms (Nuclei) stay editable while the injector is live
  • #7054 fix(security-coverage): duplicate security_coverages rows break STIX bundle processing (NonUniqueResultException)
  • #7050 fix(api): throttle post-migration full reindex to prevent DB pool exhaustion
  • #7048 fix(api): assets demoted by the taxonomy remodel are uneditable (404) and missing from inject target selection
  • #7040 fix(expectations): asset results view still displays the expiration manager entry on vulnerability expectations answered by a scanner
  • #7027 fix(api): inject global score shows PARTIAL instead of FAILED when an asset group expectation with all-assets validation mode fails
  • #7025 fix(api): collector-managed security platforms are always deletable since collectors v2 tenant activation
  • #7022 fix(expectations): expiration manager stamps redundant or contradictory results on vulnerability expectations already answered by a scanner
  • #6997 fix: real-time inject updates, expectation verdicts, tenant scoping, findings visibility and vulnerability UI fixes
  • #6961 fix(expectations): AI defense feed hands endpoint parent expectations to mismatched collectors, clobbering agent verdicts
  • #6868 fix(streaming): avoid HikariCP pool exhaustion from per-event permission checks
  • #6820 fix(scenario): adding injects to scenario (new, existing) from the threat arsenal page does not carry default expectations over
  • #6817 fix(rbac): threat arsenal seems not to be on the manager default role
  • #6778 fix(api): collector upserts restream unchanged entities and flood the event stream
  • #6710 fix(ui,docs): block broken macOS session/service-user agent install modes + update docs
  • #6337 fix(threat-library): column status is misaligned
  • #6336 fix(ui): when all entries in a burger are disabled, the burger itself should be disabled, to avoid misleading the user
  • #5805 fix: CSV export fails for users with Asset role
  • #5701 fix: unknown error when opening "Manage Grants" on any group in Settings → Security → Groups
  • #3469 fix: top margin of player creation form does not respect 20px for the first field
  • #3460 fix: results in the atomic testing header are misaligned and misplaced
  • #3415 fix: documents uploaded for injects/collectors icons should not be shown or deletable

Pull Requests:

New Contributors:

Full Changelog: 3.260729.0...3.260731.0