Skip to content

Sentinel as Code Toolkit v26.10

Latest

Choose a tag to compare

@github-actions github-actions released this 08 Oct 13:44
ffb8b05

Version 26.10.2

The October 2026 release. It combines everything from 26.10.0 and 26.10.1 with
the fixes found by a full feature test, so this one entry replaces the separate
26.10.0 and 26.10.1 notes.

Added

  • Bulk Maintenance & Validation works again. It validates, formats, or reports on
    every analytics rule in a folder, chosen from a dialog or by right-clicking a folder
    in the Explorer. Scaffolding templates and excluded files are skipped. The command
    had been listed in the Command Palette without a handler since the rebrand.

Changed

  • The minimum supported VS Code version is now 1.134 (engines.vscode
    raised from ^1.125.0), so the extension API typings can track current
    VS Code releases.
  • Development toolchain updates: @vscode/vsce 4.x (requires Node.js 22 or
    later), @vscode/test-electron 3.1, ESLint 10.11, Mocha 11.8, webpack
    5.111, webpack-cli 7.2.3, typescript-eslint 8.71, and @types/node 26.6.
  • CI now validates on Node.js 22 and 24. Node.js 20 was dropped from the
    matrix because it reached end of life and the packaging tool no longer
    supports it. actions/setup-node moved to v7 and
    softprops/action-gh-release to v3.0.2.
  • Fix Field Order is now Shift+Alt+O, so it no longer takes over Find in Files
    (Ctrl+Shift+F, or Cmd+Shift+F on macOS) in .sentinel.yaml files. The shortcut and
    the editor context menu entries now also work in .sentinel.yml files.
  • validation.onType now defaults to on, matching how validation already behaved.
  • Populate Required Data Connectors suggests each core table's native connector
    first, for example Windows Security Events for SecurityEvent rather than an
    Exchange on-premises collector.

Removed

  • The mitre.version setting. Only one MITRE ATT&CK data set ships with the
    extension, so the setting had no effect.

Fixed

  • Decompile ARM to YAML now writes MITRE technique IDs under the canonical
    relevantTechniques key instead of the deprecated techniques alias,
    matching the Sentinel-As-Code documentation, the Azure-Sentinel query style
    guide, and every analytics rule in the Sentinel-As-Code content library.
    Sub-technique IDs from the ARM subTechniques property are now folded into
    the same list (for example T1078.004 rather than a bare T1078), so
    they are no longer dropped on conversion.
    (noodlemctwoodle/Sentinel-As-Code#51)
  • Locally packaged builds no longer include leftover files from earlier
    builds. The webpack output folder is now emptied before each build, so a
    stale, unused dist/401.extension.js chunk and an outdated
    extension.js.LICENSE.txt no longer end up in the VSIX. Builds from CI
    were not affected because they start from a clean checkout.
  • Connector problems are reported again. Unknown connectors in strict or workspace
    mode, deprecated connectors, and tables a connector does not provide were never
    shown, because the validator could not find the line of a list item. Each
    unavailable table is now reported once, as a warning on its own line, and only for
    connectors whose tables are known.
  • Unknown tactics and techniques now show the information message that
    mitre.allowUnknownTactics and mitre.allowUnknownTechniques describe.
    Information-level diagnostics, including field-order hints, were previously
    discarded. fieldOrdering.showOrderHints now hides the field-order hints.
  • Field-order hints only consider top-level keys, so nested keys such as
    incidentConfiguration.groupingConfiguration.enabled no longer produce false hints.
  • Turning off validation.enabled now stops analytics rule validation, not just
    hunting query validation.
  • validation.onType and validation.onSave now control when validation runs, and
    changing any Sentinel-as-Code setting revalidates open files.
  • Validate Rule reports a pass when a rule has no errors or warnings, instead of a
    warning reading "found 0 error(s) and 0 warning(s)".
  • Only a file's own name decides whether it is treated as a Sentinel rule by name, so
    a folder with "sentinel" in its path no longer pulls in unrelated YAML files.
  • Format Content no longer fails on summary rules, automation rules, and
    watchlists authored in YAML. It explains that the YAML is not reformatted and points
    to Convert Content YAML to JSON.
  • Format Content no longer reformats unrelated JSON files and reports
    "Formatted Unknown".
  • formatting.enabled now turns off Format Document for Sentinel content, and
    fieldOrdering.enforceOrder set to off keeps the existing field order when
    formatting rules.
  • Decompile ARM to YAML keeps near-real-time rules as kind: NRT, without the
    scheduling and trigger fields. ARM exports use the kind NRT, which was converted
    to a Scheduled rule with an invented five-minute schedule.
  • conversion.validateEntityMappings now takes effect, warning about unknown entity
    types and incomplete field mappings during conversion.
  • Convert Content YAML to JSON and Convert Content JSON to YAML ask before
    overwriting an existing file.
  • intellisense.enabled now turns off Sentinel completions and hovers.

Security

  • Resolved all open Dependabot alerts. Runtime: js-yaml 4.3.2 (two high
    severity advisories). Development only: undici 7.30, fast-uri 3.1.8,
    browserslist 4.29, baseline-browser-mapping 2.11, and the braces
    advisory reachable through @vscode/vsce 3.x. npm audit reports no
    remaining vulnerabilities.
  • Reviewed the codebase with Mythos 5.1 code scanning, covering
    dependencies, YAML and JSON parsing, file writes, regular expressions,
    committed secrets, and the GitHub Actions workflows. No dependency
    vulnerabilities or committed secrets were found. The hardening items it
    identified are fixed in this release and listed below.
  • Data connector hover text is no longer rendered as trusted markdown.
    Connector details can come from a .sentinel-connectors.json file in the
    workspace, so that text is now treated as untrusted content.
  • Removed the separate weekly connector refresh workflow, which pushed
    regenerated data straight to the default branch. Connector data is still
    refreshed weekly by the data job in build.yaml, which opens a pull
    request for review.
  • The release workflow now passes inputs and job outputs to its shell
    scripts through environment variables instead of inlining them.
  • Removed tmp, an unused runtime dependency.

Installation

From VS Code Marketplace

  1. Open VS Code Extensions (Ctrl+Shift+X)
  2. Search for "Sentinel as Code Toolkit"
  3. Click Install

Manual Installation

  1. Download the .vsix file below
  2. In VS Code: Extensions, then "...", then "Install from VSIX"
  3. Select the downloaded file

Resources