Version 3.260817.0
·
10 commits
to main
since this release
Enhancements:
- #7481 feat(autonomous): allow authoring an attack-path step onto an existing event
- #7461 feat(targets): open team and person overviews from inject target results
- #7376 feat(chaining): remove ff for chaining feature
- #7339 fix(chaining): attack path: a payload not executed is tagged as detected with 30 alerts (EDR Microsoft defender)
- #7304 feat: phishing custom domains, benign URLs and findings overhaul enhancement wave
- #7275 fix(attack-path): the finding drawer never shows a producing action's run status, and renders a whole command output unclamped
- #7262 feat(scenarios): rework autonomous attack path as a launch mode of chained scenarios
- #7255 feat(frontend): compact the autonomous 'convert to manual' action and gate it on a stopped run
- #7241 fix(attack-path): the focused finding's path is never visibly highlighted (highlight equals scope)
- #7240 fix(chaining): MITRE tactic bands overlap each other on the logic map
- #7236 fix(chaining): saving an action gated by an event fails with ObjectDeletedException
- #7233 fix(chaining): stopping a simulation wipes its execution record and borrows the reset wording
- #7231 fix(attack-path): payloads attach to a shared 'localhost' node, and NetworkTraffic payloads never appear
- #7229 fix(chaining): logic map repeats the MITRE tactic on every action card
- #7223 feat(fds): replace the left navigation with the design-system Navbar
- #7203 feat(autonomous): OpenAEV-controlled run timeout with winddown steering and guaranteed termination
- #7175 fix(attack-path): selecting a collapsed finding (e.g. one port among 16) empties the causal-chain graph
- #7146 feat(injectors): built-in native phishing capability (landing pages, email templates, credential capture)
- #7109 feat(platform): implement safe-mode configuration and visual banner
- #7077 feat(output-types): add a new output processor type: ActionOutput, and check filter in conditions related to contains.
- #7075 feat(chaining): add new output type "output"
- #7073 feat(chaining): Create action from event
- #6965 feat(chaining): attack path - collectors results
- #6963 feat(chaining): attack path - remediation
- #6936 feat(chaining): add documentation for atack path
- #6935 feat(chaining): add documentation for basic chaining
- #6934 feat(chaining): add documentation for logic creation
- #6933 feat(chaining): add documentation for scope in chaining
- #6926 feat(chaining): allow linking inputs to many primitive types
- #6921 feat(chaining): Highlight the dataflow
- #6895 feat(audit-logging): Phase 2 - US1 - Chunk 4 - Inject queued for integration agent
- #6894 feat(audit-logging): Phase 2 - US1 - Chunk 3 - Scheduled execution + target resolution
- #6893 feat(audit-logging): Phase 2 - US1 - Chunk 2 - Agent trace steps
- #6892 feat(audit-logging): Phase 2 - US1 - Chunk 1 - Event logging inject status transitions
- #6862 feat(debug): make debug mode usable on high-traffic and centrally-logged instances
- #6856 feat(scope): feat(segregation-of-duties): Phase 1 - US.1 - Standalone Tag Management capability
- #6855 feat(chaining): attack path - part 1
- #6680 feat(chaining): Visualize Complete Dependency Chain
- #6600 feat(chaining): be able to execute injectors with chaining engine
- #6580 feat(chaining): refactor engine to manage correlated data
- #6536 feat(chaining): refactor chaining engine to include complex and primitives types
- #6409 feat(multitenancy): API isolation v2 executor GCatalog
- #6368 feat(audit-logging): Phase 2 - US.4 - Warning Enterprise Edition Gating
- #6357 feat(chaining): make chaining tenant compatible
- #6298 feat(chaining): event on Logic Flow
- #6297 feat(chaining): event creation drawer
- #6288 refactor(chaining): document current state storage solution
- #6198 feat(chaining): update the chaining engine to use the primitive and complex type
- #5992 feat(ask-ariane): support agent-generated file downloads from XTM One (#810)
- #5970 feat(chaining): add safety policy tooltip and information to the UI
- #5969 feat(chaining): add safety policy usage telemetry
- #5968 feat(chaining): implement safety policy simulation rate limit
- #5966 [Chaining] Safety policy - Implement default simulation timeout
- #5774 feat(chaining): scenario/simulation import/export
- #5560 Lost Connectivity Notification – OpenAEV Multi-Tenant
- #5511 docs(chaining): documentation
- #5049 feat(chaining): event creation
- #5048 feat(chaining): attack path view
- #5045 feat(chaining): logic creation
- #5043 feat(chaining): action selection
- #5042 feat(chaining): safety policy definition
- #4824 feat(chaining): basic Chaining Engine
- #4435 feat(chaining): add an EE lock on the chaining feature
- #3594 feat: add phishing injector with typosquatting ability
- #3478 feat: move create/update button on top, as in OpenCTI
- #1650 feat: add env variables handling for cookies
- #1387 feat: ability to simulate phishing campaigns
- #1192 feat: payloads can be used for phishing emails
- #227 feat: validate the regex directly when editing/creating the challenge
- #190 feat: free text field in the lessons learned
- #183 feat: launch a challenge when a previous one was validated
Bug Fixes:
- #7408 fix(chaining): simulation scope displays team/player IDs instead of names
- #7321 fix: tenant role update fails when role holds stale platform-scoped capabilities
- #7218 fix(chaining): logic view lost its per-MITRE-tactic column layout (regressed in #7099)
- #7214 fix: attack path map is unreadable when a simulation produces many finding types
- #7212 fix(chaining): logic page allows manual action→event links, and event nodes are labeled like triggers
- #7210 fix(chaining): defined value is dropped when an output type is linked on the same field
- #7209 fix(attack-path): table row click no longer focuses the graph, a focus can silently no-op, oversized picker date
- #7205 fix(attack-path): live graph stops re-framing during a run — the initial load consumes the whole camera budget
- #7204 fix(attack-path): long finding values render as a wall of text in the category panel
- #7201 fix(role): role form broken
- #7188 fix(connectors): migrating an existing collector/injector/executor reports it as "not visible in the current tenant"
- #7082 fix(scope): Non-admin user with custom role cannot delete injects from a scenario - "Element not found: Inject not found with id:" error
- #6825 fix(integrations): deleting a collector does not remove its connector instance and shows "migrate" button
- #6516 fix(import-payload): 404 when trying to use an imported payload in atomic testing
Pull Requests:
- feat(executors): align api with v2 tenant isolation (#6409) by corinnekrych (@corinnekrych) in #6811
- fix(connectors): pass TxCtx on createConnectorInstance so migrate can see the collector/injector/executor (#7188) by Sébastien MIGUEL (@Seb-MIGUEL) in #7185
- feat(autonomous): autonomous AI-driven attack path (OpenAEV substrate) (#7098) by Samuel Hassine (@SamuelHassine) in #7099
- feat(secret-providers): add secret system integration (#5536) by MarineLeM in #6914
- fix(injector-contract): dedupe attack patterns/tags/domains on the search endpoint (#7189) by Sébastien MIGUEL (@Seb-MIGUEL) in #7186
- fix(attack-path): truncate a finding panel's list items to one line (#7204) by Sébastien MIGUEL (@Seb-MIGUEL) in #7192
- fix(attack-path): highlight the causal chain when a finding is picked from a drawer/summary list (#7187) by Sébastien MIGUEL (@Seb-MIGUEL) in #7187
- fix(attack-path): only spend the live camera budget on real growth (#7205) by Sébastien MIGUEL (@Seb-MIGUEL) in #7206
- docs(injector-contract): clarify is_atomic_testing semantics (#5345) by Johanah LEKEU (@johanah29) in #7208
- fix(attack-path): restore focus-on-click from the table, and keep a focus always visible (#7209) by Sébastien MIGUEL (@Seb-MIGUEL) in #7207
- fix(chaining): keep a field's defined value when a type is also linked (#7210) by Sébastien MIGUEL (@Seb-MIGUEL) in #7211
- fix(attack-path): surface whether an execution actually ran, not just its verdict (#7194) by Sébastien MIGUEL (@Seb-MIGUEL) in #7194
- fix(chaining): forbid manual action->event links and label event nodes as events (#7212) by Sébastien MIGUEL (@Seb-MIGUEL) in #7213
- fix(chaining): lay the logic graph out in MITRE-tactic columns (#7218) by Sébastien MIGUEL (@Seb-MIGUEL) in #7219
- feat(autonomous): OpenAEV-controlled run timeout, live attack path and scoped expectations (#7203) by Samuel Hassine (@SamuelHassine) in #7216
- fix(threat-arsenal): rewrite embedded contract_id when importing threats (#6516) by Gabriel Pezé (@gabriel-peze) in #7217
- fix(attack-path): keep the map legible when a simulation produces many finding types (#7214) by Sébastien MIGUEL (@Seb-MIGUEL) in #7215
- fix(autonomous): allow restarting a run from any state (#7220) by Samuel Hassine (@SamuelHassine) in #7221
- fix(deps): update dependency @hookform/resolvers to v5.7.1 by renovate[bot] in #7224
- fix(deps): update dependency react-intl to v10.1.20 by renovate[bot] in #7225
- feat(autonomous): convert-to-manual, legible logic layout, compact attack-path header, readable events (#7226) by Samuel Hassine (@SamuelHassine) in #7227
- fix(executor): missed API (#6409) by corinnekrych (@corinnekrych) in #7228
- fix(chaining): lay the logic map back out as one column per MITRE tactic (#7240) by Sébastien MIGUEL (@Seb-MIGUEL) in #7238
- docs: overhaul documentation structure, content, and screenshots by Romuald Lemesle (@RomuDeuxfois) in #7125
- fix(attack-path): restore per-node drag-and-drop in canvas by Murat Arslan (@mergenhan) in #7247
- chore(ci): improve ci speed and reliability (#7117) by Guillaume (@guillaumejparis) in #6396
- feat(platform): implement safe-mode configuration and visual banner (#7109) by Stephanya Casanova (@savacano28) in #7181
- fix(roles): set description nullish (#7201) by Gabriel Pezé (@gabriel-peze) in #7249
- fix(attack-path): keep non-producing actions off a focused finding's path (#7241) by Sébastien MIGUEL (@Seb-MIGUEL) in #7242
- fix(chaining): show the MITRE tactic only on the column, not on every card (#7229) by Sébastien MIGUEL (@Seb-MIGUEL) in #7230
- fix(attack-path): trace the highlighted path on the connectors, not just the cards (#7253) by Sébastien MIGUEL (@Seb-MIGUEL) in #7254
- feat(front): compact convert-to-manual action, gate on stopped run (#7255) by Samuel Hassine (@SamuelHassine) in #7256
- fix(chaining): addback lock banner on logic map and fix issue blocking edit after reset (#5045) by Hedi (@heditar) in #7235
- fix(attack-path): frame the highlighted path around the selected finding (#7257) by Sébastien MIGUEL (@Seb-MIGUEL) in #7258
- fix(chaining): keep a preserved event's whole tree when saving a step (#7236) by Sébastien MIGUEL (@Seb-MIGUEL) in #7237
- chore(deps): update dependency com.tngtech.archunit:archunit-junit5 to v1.5.0 by renovate[bot] in #7265
- fix(deps): update dependency com.microsoft.playwright:playwright to v1.62.0 by renovate[bot] in #7264
- fix(deps): update dependency software.amazon.awssdk:bom to v2.50.3 by renovate[bot] in #7261
- fix(deps): update dependency dompurify to v3.4.13 by renovate[bot] in #7259
- chore(deps): update actions/github-script action to v9 by renovate[bot] in #7260
- chore: update and fix ci & docker compose (#7117) by Guillaume (@guillaumejparis) in #7250
- feat(audit-logging): phase 2 - US1 - Chunk 1 - Event logging inject status transitions (#6892) by Gael Leblan (@Dimfacion) in #6900
- feat(audit-logging): phase 2 - US1 - Chunk 2 - Agent trace steps (#6893) by damgouj (@damgouj) in #7267
- feat(audit-logging): phase 2 - US1 - Chunk 4 - Inject queued for agents (#6895) by damgouj (@damgouj) in #7272
- feat(credentials): implement CRUD (#5536) by MarineLeM in #7127
- fix(workflows): escape square brackets in workflow names (#7117) by Guillaume (@guillaumejparis) in #7277
- feat(audit-logging): phase 2 - US1 - Chunk 3 - Scheduled execution + target resolution (#6894) by damgouj (@damgouj) in #7271
- chore(ai): update copilot review skill to check for v2 api (#7244) by corinnekrych (@corinnekrych) in #7246
- feat(autonomous): make autonomy a launch mode of chained scenarios (#7262) by Samuel Hassine (@SamuelHassine) in #7263
- fix(scenario): route manual chained launch to the simulation attack path (#7286) by Samuel Hassine (@SamuelHassine) in #7287
- fix(autonomous): resume status on directive, idle caption guard, plan-mode time budget (#7290) by Samuel Hassine (@SamuelHassine) in #7291
- fix(autonomous): decouple scenario deletion from simulation lifecycle (#7295) by Samuel Hassine (@SamuelHassine) in #7296
- fix(autonomous): plan mode has no time budget; autonomous defaults to 24h over scenario config (#7297) by Samuel Hassine (@SamuelHassine) in #7298
- fix(chaining): stop a simulation without erasing what it produced (#7233) by Sébastien MIGUEL (@Seb-MIGUEL) in #7234
- chore(ci): improve fail speed and fix GHCR rate limiting (#7117) by Guillaume (@guillaumejparis) in #7289
- fix(chaining): credential finding and chokepoint highlighting is not working (#5048) by Murat Arslan (@mergenhan) in #7278
- fix(attack-path): ship each execution's run status with the graph, and clamp a long finding value (#7275) by Sébastien MIGUEL (@Seb-MIGUEL) in #7276
- fix(chaining): enforce EE license on chaining creation and import (#4435) by Hedi (@heditar) in #7282
- fix(attack-path): resolve a payload's real target instead of its payload default (#7231) by Sébastien MIGUEL (@Seb-MIGUEL) in #7232
- docs(chaining): document execution flow (#5511) by Godstime Aburu (@BboyGT) in #6524
- feat(chaining): display payload self execution (OpenAEV-Platform/filigran-private#259) by EvaE-Filigran in #7283
- fix(audit-log): cap request payload size for multipart endpoints (#7269) by Gabriel Pezé (@gabriel-peze) in #7279
- feat(phishing): add built-in native phishing capability (#7146) by Samuel Hassine (@SamuelHassine) in #7149
- feat: phishing custom domains, benign URLs and findings overhaul (#7304) by Samuel Hassine (@SamuelHassine) in #7303
- fix(deps): update dependency io.pyroscope:agent to v2.9.0 by renovate[bot] in #7301
- fix(deps): update dependency software.amazon.awssdk:bom to v2.51.2 by renovate[bot] in #7300
- chore(deps): update dependency ipaddr.js to v2.5.0 by renovate[bot] in #7293
- chore(deps): update devdependencies (non-major) by renovate[bot] in #7292
- chore(deps): update opensearchproject/opensearch docker tag to v3.8.0 by renovate[bot] in #7299
- fix(phishing): fill editor preview pane and use design-system chips (#7306) by Samuel Hassine (@SamuelHassine) in #7307
- chore(deps): lock file maintenance by renovate[bot] in #7294
- fix(model): remove duplicate Ivan Dyachkov (@id) from ConnectorInstance by Romuald Lemesle (@RomuDeuxfois) in #6886
- fix(workflows): read PR labels live in documentation gap check by Romuald Lemesle (@RomuDeuxfois) in #7308
- fix(inject): scope bulk inject update/delete to scenario and simulation APIs (#7082) by Romuald Lemesle (@RomuDeuxfois) with @Copilot in #7184
- fix(phishing): fill inline editor preview via absolute iframe (#7309) by Samuel Hassine (@SamuelHassine) in #7310
- fix(phishing): resolve recipient team name to id for phishing_results (#7311) by Samuel Hassine (@SamuelHassine) in #7312
- feat(attack-path): causal seed generator (#6855) by Laurent Giovannoni (@laugiov) in #7139
- feat(debug): configurable SQL log rotation, caller (user) in trace, ORM summary to file (#6862) by Laurent Giovannoni (@laugiov) in #6863
- fix(phishing): surface findings and score three inverted awareness steps (#7313) by Samuel Hassine (@SamuelHassine) in #7314
- fix(chaining): fix rbac on chaining (#4824) by Camille Roux (@camrrx) in #7190
- fix: show action and event configurations even if simulation is locked (#5045) by Stephanya Casanova (@savacano28) in #7315
- fix(notification): reject internal address forms missed by the webhook target guard by Laurent Giovannoni (@laugiov) in #7319
- fix(connector): only check jwks for connector tied to requested tenant (#7180) by antoinemzs in #7178
- fix(attack-path): removed password_policy masking from the attack path view (#5048) by Yann (@impolitepanda) in #7318
- fix: paginate finding drawer correctly in attack path view (#5048) by Stephanya Casanova (@savacano28) in #7317
- fix(chaining): make chained simulations imported with a scope runnable (#234) by Yann (@impolitepanda) in #7154
- fix: phishing expectation reconciliation, attack-path action nodes/icons and expectation display-merge leak (#7322) by Samuel Hassine (@SamuelHassine) in #7323
- fix(deps): update dependency software.amazon.awssdk:bom to v2.51.3 by renovate[bot] in #7325
- fix(deps): update dependency org.apache.commons:commons-collections4 to v4.6.0 by renovate[bot] in #7327
- fix(deps): update dependency org.bouncycastle:bc-jdk18on-bom to v1.85.2 by renovate[bot] in #7324
- fix(deps): update dependency io.opentelemetry:opentelemetry-bom to v1.65.0 by renovate[bot] in #7326
- fix(deps): update dependency react-hook-form to v7.85.0 by renovate[bot] in #7328
- fix: phishing, attack-path and home-dashboard enhancements wave (#7320) by Samuel Hassine (@SamuelHassine) in #7332
- chore(security_coverage): add logs for security coverage job class (#6284) by damgouj (@damgouj) in #7333
- fix(workflows): ignore unfixed findings in container vulnerability scan by Romuald Lemesle (@RomuDeuxfois) in #7334
- fix(threat-arsenal): attack-path execution fallback and phishing Credentials output (#7337) by Samuel Hassine (@SamuelHassine) in #7338
- fix(dashboard): make home resilience gauge row responsive to gauge count (#7342) by Samuel Hassine (@SamuelHassine) in #7343
- feat(scope): capability and grant holder cannot grant a capability or grant they don't hold (#7197) (#7198) by damgouj (@damgouj) in #7280
- test(rbac): fix phishing roles migration test after RoleService rename (#7351) by Samuel Hassine (@SamuelHassine) in #7352
- fix(injectors): remove user variables from multi-recipients email contract cheat sheet (#3878) by Samuel Hassine (@SamuelHassine) in #7346
- fix(threatarsenal): slim the pagination toolbar so the create button stays accessible (#7340) by Samuel Hassine (@SamuelHassine) in #7355
- fix(injects): show deprecated payload indicator in inject lists and atomic testing (#3839) by Samuel Hassine (@SamuelHassine) in #7345
- fix(chaining): show logic map links (#5045) by Stephanya Casanova (@savacano28) in #7348
- feat(challenges): validate regex flags when creating or editing a challenge (#227) by Samuel Hassine (@SamuelHassine) in #7358
- fix(injects): apply asset bulk updates only to contracts with asset fields (#2165) by Samuel Hassine (@SamuelHassine) in #7344
- fix(chaining): resolve target dns resolution for attack path by EvaE-Filigran in #7362
- fix(executors): stop SentinelOne agent sync crashing on missing pagination and stacked cursors by Romuald Lemesle (@RomuDeuxfois) in #7361
- fix(threat-arsenal): unblock orchestrator - drop redundant DISTINCT in findings search and null-guard payload id lists (#7363) by Samuel Hassine (@SamuelHassine) in #7364
- fix(deps): pin velocity-engine-core to 2.4.1 by Romuald Lemesle (@RomuDeuxfois) in #7360
- fix(rbac): lenient scope filtering on role capability update (#7321) by Romuald Lemesle (@RomuDeuxfois) in #7329
- fix(front): gate scenario hero AI actions on XTM One availability and EE (#7368) by Samuel Hassine (@SamuelHassine) in #7369
- fix(front): responsive autonomous-attack agent list and live heartbeat handling (#7370) by Samuel Hassine (@SamuelHassine) in #7371
- fix(front): stop heartbeats polluting the autonomous decision timeline (#7381) by Samuel Hassine (@SamuelHassine) in #7382
- docs(threat-arsenal): split the Actions page and refresh its screenshots by Romuald Lemesle (@RomuDeuxfois) in #7365
- fix(front): keep the scenario overview while AI planning is active (#7386) by Samuel Hassine (@SamuelHassine) in #7387
- feat(logs): log tenant access denials with caller and request context by Romuald Lemesle (@RomuDeuxfois) in #7377
- fix(credentials): add telemetry + audit log (#5536) by MarineLeM in #7354
- fix(chaining): scenario import not working when multiple injector types for a same tenant exist (#5048) by Yann (@impolitepanda) in #7379
- feat(chaining): snapshot scope rules and security platforms of launched simulations (#5508) by EvaE-Filigran in #7252
- fix(autonomous): scrollable orchestrator drawer and run lifecycle guards (#7390) by Samuel Hassine (@SamuelHassine) in #7391
- fix(executor): reimplement GC collector behavior to SentinelOne executor (#6854) by Gaetan Santucci (@GaetanSantucci) in #7378
- feat: unblock execution when input are not mandatories (#4824) by Stephanya Casanova (@savacano28) in #7388
- fix(autonomous): RBAC, event-sequence serialization, status validation, IPv6 scope (#7390) by Samuel Hassine (@SamuelHassine) in #7394
- fix(credentials): add credentials capability (#5536) by MarineLeM in #7330
- fix(chaining): consume team and player scope for tabletop actions (OpenAEV-Platform/filigran-private#308) by Samuel Hassine (@SamuelHassine) in #7398
- fix(chaining): hide Pause CTA for chained simulations and return 400 instead of 500 (#307) by Yann (@impolitepanda) in #7403
- fix(chaining): update targets on action when adding an asset (#5045) by Camille Roux (@camrrx) in #7395
- fix(chaining): resolve team and player names in simulation scope snapshots (#7408) by Samuel Hassine (@SamuelHassine) in #7409
- fix(chaining): deserialize inject document attachments in step data (#7410) by Samuel Hassine (@SamuelHassine) in #7411
- fix(api): stop connection leaks and OpenCTI coverage spam during AI arsenal writes (#7415) by Samuel Hassine (@SamuelHassine) in #7416
- fix(chaining): cascade-delete template steps when their injector contract or payload is deleted (#7412) by Samuel Hassine (@SamuelHassine) in #7413
- fix(api): return 400 not 404 when duplicating a native threat arsenal item (#7423) by Samuel Hassine (@SamuelHassine) in #7424
- fix(deps): update dependency software.amazon.awssdk:bom to v2.51.4 by renovate[bot] in #7421
- fix(chaining): harden inject deserialization and step authoring against desyncs and deleted contracts (#7414, #7418) by Samuel Hassine (@SamuelHassine) in #7426
- fix(api): guard null inject content in DNS indicator coverage (#7422) by Samuel Hassine (@SamuelHassine) in #7425
- feat(multitenancy): activate api v2 isolation for injectors and connector_instances (#6410) by corinnekrych (@corinnekrych) in #7059
- chore(deps): update dependency net.javacrumbs.json-unit:json-unit-assertj to v6.1.0 by renovate[bot] in #7420
- revert: pull api v2 injectors/connector_instances out of the release (#7059) by Laurent Giovannoni (@laugiov) in #7431
- fix(chaining): fix event filtering (#5049) by Hedi (@heditar) in #7406
- docs(chaining): attack chaining documentation (#5511) by Stephanya Casanova (@savacano28) in #7374
- feat: update chaining doc (#5511) by Stephanya Casanova (@savacano28) in #7436
- feat(chaining): remove feature flag for chaining (#7376) by Stephanya Casanova (@savacano28) in #7380
- feat(audit-logging): Warning Enterprise Edition Gating (#6368) by Johanah LEKEU (@johanah29) in #6807
- fix(autonomous): activate multi-tenancy v2 tenant isolation on autonomous tables (#7396) by Samuel Hassine (@SamuelHassine) in #7430
- fix(autonomous): observable runs via idle watchdog, cockpit fallback and actionable arsenal 400 (#7443) by Samuel Hassine (@SamuelHassine) in #7445
- feat(autonomous): render live orchestrator activity in the reasoning window (#7446) by Samuel Hassine (@SamuelHassine) in #7447
- fix(autonomous): anchor the cockpit reasoning caption to real activity (#7448) by Samuel Hassine (@SamuelHassine) in #7449
- fix(autonomous): treat live pulse as active work in delegation phase (#7454) by Samuel Hassine (@SamuelHassine) in #7455
- fix(autonomous): collapse duplicate captions in the cockpit thinking window (#7452) by Samuel Hassine (@SamuelHassine) in #7453
- fix(autonomous): authorize orchestrator callbacks from the parent run tenant (#7450) by Samuel Hassine (@SamuelHassine) in #7451
- fix(platform): summarize validation 400s and fix attack-path grid UX (#7459) by Samuel Hassine (@SamuelHassine) in #7460
- feat(targets): open team and person overviews from inject target results (#7461) by Samuel Hassine (@SamuelHassine) in #7462
- fix(expectations): resisted-outcome phishing step names and contract-declared ordering (#7463) by Samuel Hassine (@SamuelHassine) in #7464
- fix(api): return actionable message on method-level validation 400 (#7466) by Samuel Hassine (@SamuelHassine) in #7467
- fix(phishing): ignore scanner probes in scoring and surface step forensics (#7470) by Samuel Hassine (@SamuelHassine) in #7471
- fix(autonomous): keep AI scenario cockpit reliable - tooltip, reload, scope 500 (#7472) by Samuel Hassine (@SamuelHassine) in #7473
- fix(deps): update dependency @hookform/resolvers to v5.8.0 by renovate[bot] in #7474
- fix(deps): update dependency html-react-parser to v6.1.7 by renovate[bot] in #7468
- fix(deps): update dependency zustand to v5.0.15 by renovate[bot] in #7458
- chore(deps): update dependency net.javacrumbs.json-unit:json-unit-assertj to v6.2.0 by renovate[bot] in #7469
- chore(deps): update devdependencies (non-major) by renovate[bot] in #7456
- fix(deps): update logback monorepo to v1.6.2 by renovate[bot] in #7438
- fix(deps): update dependency software.amazon.awssdk:bom to v2.53.0 by renovate[bot] in #7439
- fix(deps): update dependency co.elastic.clients:elasticsearch-java to v8.19.20 by renovate[bot] in #7437
- fix(deps): update dependency @xyflow/react to v12.11.3 by renovate[bot] in #7441
- fix(api): drop tunnel pseudo-interface MAC addresses at registration (#311) by Laurent Giovannoni (@laugiov) in #7429
- fix(autonomous): prevent phantom-flush StaleStateException on autonomous run reads (#7476) by Samuel Hassine (@SamuelHassine) in #7477
- chore(deps): lock file maintenance by renovate[bot] in #7457
- feat(segregation-of-duties): Standalone Tag Management capability (#6856) by Johanah LEKEU (@johanah29) in #6897
- feat(chaining): add a chain/tactic layout switcher to the Logic tab (#7479) by Samuel Hassine (@SamuelHassine) in #7480
- feat(autonomous): allow authoring an attack-path step onto an existing event (#7481) by Samuel Hassine (@SamuelHassine) in #7482
New Contributors:
- Godstime Aburu (@BboyGT) made their first contribution in #6524
Full Changelog: 3.260805.0...3.260817.0