Repository navigation
Version 26.10.2
The October 2026 release. It combines everything from 26.10.0 and 26.10.1 with
the fixes found by a full feature test, so this one entry replaces the separate
26.10.0 and 26.10.1 notes.
Added
- Bulk Maintenance & Validation works again. It validates, formats, or reports on
every analytics rule in a folder, chosen from a dialog or by right-clicking a folder
in the Explorer. Scaffolding templates and excluded files are skipped. The command
had been listed in the Command Palette without a handler since the rebrand.
Changed
- The minimum supported VS Code version is now 1.134 (
engines.vscode
raised from^1.125.0), so the extension API typings can track current
VS Code releases. - Development toolchain updates:
@vscode/vsce4.x (requires Node.js 22 or
later),@vscode/test-electron3.1, ESLint 10.11, Mocha 11.8, webpack
5.111, webpack-cli 7.2.3, typescript-eslint 8.71, and@types/node26.6. - CI now validates on Node.js 22 and 24. Node.js 20 was dropped from the
matrix because it reached end of life and the packaging tool no longer
supports it.actions/setup-nodemoved to v7 and
softprops/action-gh-releaseto v3.0.2. - Fix Field Order is now Shift+Alt+O, so it no longer takes over Find in Files
(Ctrl+Shift+F, or Cmd+Shift+F on macOS) in.sentinel.yamlfiles. The shortcut and
the editor context menu entries now also work in.sentinel.ymlfiles. validation.onTypenow defaults to on, matching how validation already behaved.- Populate Required Data Connectors suggests each core table's native connector
first, for example Windows Security Events forSecurityEventrather than an
Exchange on-premises collector.
Removed
- The
mitre.versionsetting. Only one MITRE ATT&CK data set ships with the
extension, so the setting had no effect.
Fixed
- Decompile ARM to YAML now writes MITRE technique IDs under the canonical
relevantTechniqueskey instead of the deprecatedtechniquesalias,
matching the Sentinel-As-Code documentation, the Azure-Sentinel query style
guide, and every analytics rule in the Sentinel-As-Code content library.
Sub-technique IDs from the ARMsubTechniquesproperty are now folded into
the same list (for exampleT1078.004rather than a bareT1078), so
they are no longer dropped on conversion.
(noodlemctwoodle/Sentinel-As-Code#51) - Locally packaged builds no longer include leftover files from earlier
builds. The webpack output folder is now emptied before each build, so a
stale, unuseddist/401.extension.jschunk and an outdated
extension.js.LICENSE.txtno longer end up in the VSIX. Builds from CI
were not affected because they start from a clean checkout. - Connector problems are reported again. Unknown connectors in strict or workspace
mode, deprecated connectors, and tables a connector does not provide were never
shown, because the validator could not find the line of a list item. Each
unavailable table is now reported once, as a warning on its own line, and only for
connectors whose tables are known. - Unknown tactics and techniques now show the information message that
mitre.allowUnknownTacticsandmitre.allowUnknownTechniquesdescribe.
Information-level diagnostics, including field-order hints, were previously
discarded.fieldOrdering.showOrderHintsnow hides the field-order hints. - Field-order hints only consider top-level keys, so nested keys such as
incidentConfiguration.groupingConfiguration.enabledno longer produce false hints. - Turning off
validation.enablednow stops analytics rule validation, not just
hunting query validation. validation.onTypeandvalidation.onSavenow control when validation runs, and
changing any Sentinel-as-Code setting revalidates open files.- Validate Rule reports a pass when a rule has no errors or warnings, instead of a
warning reading "found 0 error(s) and 0 warning(s)". - Only a file's own name decides whether it is treated as a Sentinel rule by name, so
a folder with "sentinel" in its path no longer pulls in unrelated YAML files. - Format Content no longer fails on summary rules, automation rules, and
watchlists authored in YAML. It explains that the YAML is not reformatted and points
to Convert Content YAML to JSON. - Format Content no longer reformats unrelated JSON files and reports
"Formatted Unknown". formatting.enablednow turns off Format Document for Sentinel content, and
fieldOrdering.enforceOrderset to off keeps the existing field order when
formatting rules.- Decompile ARM to YAML keeps near-real-time rules as
kind: NRT, without the
scheduling and trigger fields. ARM exports use the kindNRT, which was converted
to a Scheduled rule with an invented five-minute schedule. conversion.validateEntityMappingsnow takes effect, warning about unknown entity
types and incomplete field mappings during conversion.- Convert Content YAML to JSON and Convert Content JSON to YAML ask before
overwriting an existing file. intellisense.enablednow turns off Sentinel completions and hovers.
Security
- Resolved all open Dependabot alerts. Runtime:
js-yaml4.3.2 (two high
severity advisories). Development only:undici7.30,fast-uri3.1.8,
browserslist4.29,baseline-browser-mapping2.11, and thebraces
advisory reachable through@vscode/vsce3.x.npm auditreports no
remaining vulnerabilities. - Reviewed the codebase with Mythos 5.1 code scanning, covering
dependencies, YAML and JSON parsing, file writes, regular expressions,
committed secrets, and the GitHub Actions workflows. No dependency
vulnerabilities or committed secrets were found. The hardening items it
identified are fixed in this release and listed below. - Data connector hover text is no longer rendered as trusted markdown.
Connector details can come from a.sentinel-connectors.jsonfile in the
workspace, so that text is now treated as untrusted content. - Removed the separate weekly connector refresh workflow, which pushed
regenerated data straight to the default branch. Connector data is still
refreshed weekly by the data job inbuild.yaml, which opens a pull
request for review. - The release workflow now passes inputs and job outputs to its shell
scripts through environment variables instead of inlining them. - Removed
tmp, an unused runtime dependency.
Installation
From VS Code Marketplace
- Open VS Code Extensions (Ctrl+Shift+X)
- Search for "Sentinel as Code Toolkit"
- Click Install
Manual Installation
- Download the
.vsixfile below - In VS Code: Extensions, then "...", then "Install from VSIX"
- Select the downloaded file