Skip to content

v0.3.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Aug 05:21
a83e21f

0.3.0 (2026-07-31)

Features

  • add capec taxonomy pack (a34447b)
  • add capec taxonomy pack (53dd92b)
  • add cwe taxonomy pack (7878e77)
  • add cwe taxonomy pack (f56562e)
  • add CycloneDX 2.0 TM-BOM import/export with schema enrichments; Closes #129 (b2548b1)
  • add due date, external ticket URL, and comment log to countermeasures; implement risk register with auto-populate and kanban view (d055ad2)
  • add due date, external ticket URL, and comment log to countermeasures; implement risk register with auto-populate and kanban view (cb5c150)
  • add mitre-atlas taxonomy pack (f3f8456)
  • add mitre-atlas taxonomy pack (83d0a1b)
  • add mitre-attack taxonomy pack (4bf0068)
  • add mitre-attack taxonomy pack (f947938)
  • ai: Add a new LLM based threat suggestor (ad76e0f)
  • ai: Add a new LLM based threat suggestor (90014bf)
  • ai: add per-tenant bring-your-own-model backend infrastructure (c8fccf3)
  • ai: add per-tenant bring-your-own-model backend infrastructure (5478316)
  • ai: add the AI usage report tab to settings (84c1881)
  • ai: meter per-org AI token usage and expose a summary endpoint (aa7d16a)
  • ai: per-org AI usage tracking with usage report (3ce94cc)
  • ai: per-tenant AI provider settings API and UI (a6e81b1)
  • ai: per-tenant AI provider settings API and UI (16889b6)
  • ai: per-tenant bring-your-own-model backend infrastructure (3133cb3)
  • ai: redesign owl mark for clearer AI affordance (4e5d0d6)
  • ai: redesign owl mark for clearer AI affordance (#179) (51bcf3e)
  • align signed-in DFD editor with guest editor UX (export, CTA, notation) (7846b86)
  • auto-enter inline editing mode when dropping elements on canvas (#243) (5b77441)
  • dfd-editor: add DFD notation switching (DFD3 / Yourdon-DeMarco) (71edeaf)
  • dfd-editor: show threats on DFD canvas and improve deletion UX (fixes #2) (5582444)
  • guest-editor: add countermeasures, threat analysis screen, and TM-Library file format (7b7a299)
  • guest-editor: add STRIDE category selection to threat dialog (0fbfed8)
  • guest-editor: add STRIDE category selection to threat dialog (11d999b)
  • guest-editor: add Word report download for guest users (2a4cff3)
  • guest-editor: add Word report download for guest users (2125897)
  • guest-editor: CycloneDX TM-BOM local save/open with File System Access API (#140) (0969352)
  • guest-editor: embed DFD diagram image in guest Word report (#188) (aa81659)
  • guest-editor: embed DFD diagram image in guest Word report (#188) (14e60c8)
  • inline label editing on node drop and double-click (issue #236) (c64da09)
  • make context button more discoverable in guest editor (#244) (fec7ee9)
  • match draw.io canvas interaction model (#82) (bd7bc03)
  • pentests: add Scope sub-tab to Pentests workspace tab (cf54537)
  • reports: add CSV and Word export to report view (dde639f)
  • reports: add CSV and Word export to report view (34e5a53), closes #8
  • risk-analysis: improve Add Risk dialog UX and validation; Add r… (b4fa251)
  • risk-analysis: improve Add Risk dialog UX and validation; Add required field indicators, scoring metadata validation, toast error feedback, DialogDescription for accessibility, and threat (6e27ad0)
  • show threat description text in properties panel and improve layout(#245) (987a013)
  • unify countermeasure models with cross-type sharing and orphan … (786c207)
  • unify countermeasure models with cross-type sharing and orphan cleanup; remove in_progress status (e2eced7)

Bug Fixes

  • add 6 missing ATT&CK entries referenced by existing threat libraries (a1602fa)
  • add 9 missing CWE entries referenced by existing threat libraries (762c690)
  • add security_team bypass to dashboard stats view (03ca2b5)
  • add security_team bypass to dashboard stats view (f081404)
  • Add skeletons to all the pages instead of bare spinners, also make the toast data match backend response (7b7da9a)
  • api/schema stale field error and drift in docs (b07d841)
  • api/schema stale field error and drift in docs (8acee44)
  • auth: use JWT for password change and validate current password (1a62316)
  • center toolbar (0e78973)
  • default trust zone to untrusted (red, TL:25) instead of trusted (green, TL:75) (b9f4251)
  • dfd-editor: apply fitView zoom cap to signed-in editor (#184) (132b475)
  • dfd-editor: process node rendering and initial zoom (#184, #192, #193) (46c59ac)
  • dfd-editor: process node rendering and initial zoom. (8703153)
  • improve data flow edge label readability (#246) (0fad336)
  • improve organization member role dropdown (64f19b2)
  • include business_unit_label in organization list API response (a0f149c)
  • include business_unit_label in organization list API response (5a68e49)
  • messaging (f096765)
  • messaging (132db91)
  • more messaging tweaks (576c738)
  • more messaging tweaks (cde97b2)
  • mouse wheel not scrolling CommandList inside Popover (#155) (e5a1fea)
  • New elements appear in the middle of the screen (7ffdb3a)
  • packs: resolve BCI-Mini validation errors (b754fa2)
  • packs: resolve BCI-Mini validation errors (473387a)
  • remove unused DiagramNodeType imports (0bc6e1b)
  • remove unused DiagramNodeType imports (29e1df0)
  • resolve TypeScript build errors for Vercel deployment (de64e1b)
  • resolve TypeScript build errors for Vercel deployment (480bc18)
  • risks: remove auto-populate feature from risk register (#124) (6740dac)
  • threats: replace nested <button> with <div> in ComponentTreeItem (8f8e536)
  • tm-bom: fix DFD component_id remapping and control-threat links … (e07ddfa)
  • tm-bom: fix DFD component_id remapping and control-threat links on CycloneDX import (e9ebed3)
  • unused variable build error (4c676e8)
  • use hook-based getNodesBounds for subflow support, fix nested bu… (ef899c4)
  • use hook-based getNodesBounds for subflow support, fix nested button HTML, and add guest editor toolbar/auth improvements (aa7a872)
  • validate owning_team belongs to same org on threat model creation (f04895f)
  • validate owning_team belongs to same org on threat model creation (0d56097)
  • validate owning_team org match on threat model update (0ae0f7a)
  • validate owning_team org match on threat model update (9150156)