What's Changed
- feat: close the advisory to release gaps in the many-to-many model by @aurangzaib048 in #1465
- fix(api): a Redis blip refuses requests with a 429, not a 500 by @aurangzaib048 in #1474
- build(deps): bump the bun group across 1 directory with 14 updates by @dependabot[bot] in #1473
- fix(e2e): give the advisory fixtures distinct timestamps by @aurangzaib048 in #1472
- Keep OIDC publish tokens off the expiry bell by @aurangzaib048 in #1475
- docs: settle the glossary in AGENTS.md by @aurangzaib048 in #1476
- feat: is_default_workspace beside is_default_team, and the on-screen copy by @aurangzaib048 in #1477
- fix(spdx3): read the spec's field names, resolve every legal Agent shape by @aurangzaib048 in #1482
- fix(spdx3): the BOM subject is rootElement, not whichever package came first by @aurangzaib048 in #1483
- build(deps): bump the github-actions group with 3 updates by @dependabot[bot] in #1497
- build(deps): bump the bun group with 3 updates by @dependabot[bot] in #1496
- fix(api): give every error a code, and a status that matches it by @aurangzaib048 in #1478
- feat(api): serve a v2 that says workspace, from the same views by @aurangzaib048 in #1479
- chore(db): name the workspace tables workspace by @aurangzaib048 in #1480
- fix(spdx3): three single-field reads pointed at properties the spec has by @aurangzaib048 in #1484
- test(spdx3): a conformant corpus the plugins cannot drift from by @aurangzaib048 in #1485
- feat(spdx3): validate 3.0.1 claims against the vendored schema, speak clearly at the version edges by @aurangzaib048 in #1486
- refactor(spdx3): one detector, honest edge messages, 453 dead lines gone by @aurangzaib048 in #1487
- build(deps): bump the bun group with 8 updates by @dependabot[bot] in #1509
- fix(auth): the authorize URL stops relying on + meaning a space by @aurangzaib048 in #1501
- build(deps): bump the bun group across 1 directory with 12 updates by @dependabot[bot] in #1515
- build(deps): bump oven/bun from
5bb0f9bto8a74444in the docker group by @dependabot[bot] in #1514 - fix: prevent sidebar flash during page navigation by @lucasclgibson in #1516
- fix(billing): deleting a workspace cancels its subscription by @aurangzaib048 in #1513
- feat(api): security advisories get an API by @aurangzaib048 in #1508
- feat(vex): honour the VEX an SPDX 3 document carries about itself by @aurangzaib048 in #1505
- feat(spdx3): resolve licence relationships to expressions, not booleans by @aurangzaib048 in #1488
- fix(deps): bump fast-uri override to 3.1.6 to clear High advisories by @vpetersson-bot in #1518
- fix(trust-center): a release page does not publish vulnerabilities until asked by @aurangzaib048 in #1520
- fix(vulns): an advisory body is prose on the page, not its own markup by @aurangzaib048 in #1521
- fix(vex): the preview counts advisories, not scan rows by @aurangzaib048 in #1522
- fix(upload): the declared artifact type has to match the document by @aurangzaib048 in #1523
- fix(trust-center): a withdrawn advisory says so on the list, not only on its page by @aurangzaib048 in #1526
- feat(api): advisories can be deleted through the API that creates them by @aurangzaib048 in #1529
- fix(exports): a CSV export must not sit in a shared cache by @aurangzaib048 in #1527
- fix(vex): a statement matches every id the advisory is known by by @aurangzaib048 in #1532
- fix(sbom): emit Go major-version suffix in the shipped binaries' PURLs by @vpetersson-bot in #1519
- fix(trust-center): a count of one reads as one by @aurangzaib048 in #1536
- fix(vulns): a fixed finding no longer reads as not affected by @aurangzaib048 in #1537
- test(trust-center): posture toggle authz, and the workspace delete cascade by @aurangzaib048 in #1538
- fix(billing): deleting a workspace from settings cancels its subscription by @aurangzaib048 in #1540
- test(billing): a webhook for a deleted workspace is acknowledged by @aurangzaib048 in #1541
- fix(copy): counts agree with the nouns beside them by @aurangzaib048 in #1543
- fix(trust-center): the release VEX download respects component visibility by @aurangzaib048 in #1544
- fix(billing): settings reaches Stripe once, and only where it shows by @aurangzaib048 in #1545
- test(advisories): a guest cannot read, and bot is not a role to hand out by @aurangzaib048 in #1542
- fix(billing): bound how long a Stripe request may take by @aurangzaib048 in #1535
- build(deps): bump the bun group with 5 updates by @dependabot[bot] in #1525
- build(deps): bump oven/bun from
8a74444to4f6e31din the docker group by @dependabot[bot] in #1524 - feat(scanning): scan SPDX 3 through a derived copy instead of skipping it by @aurangzaib048 in #1502
- feat(scanning): Dependency Track reads SPDX through a derived CycloneDX copy by @aurangzaib048 in #1503
- test(throttling): cover what happens when the throttle backend is down by @aurangzaib048 in #1546
- fix(sboms): an SPDX upload that fails on our side leaves a record by @aurangzaib048 in #1549
- fix(sboms): follow an SPDX 3 document that roots itself on its Sbom by @aurangzaib048 in #1550
- fix(sboms): read the SPDX subject from the relationship Yocto actually writes by @aurangzaib048 in #1547
- fix(core): a scan every provider declined is not a clean scan by @aurangzaib048 in #1548
- fix(vulns): a suppressed finding is not a vulnerability count by @aurangzaib048 in #1551
- fix(plugins): an external-reference type written as an IRI is the same type by @aurangzaib048 in #1552
- feat(deploy): Helm chart for running sbomify on Kubernetes by @vpetersson-bot in #1429
- fix(sboms): the vulnerabilities page says which advisories the scan cleared by @aurangzaib048 in #1553
- fix(ui): the delete confirmation's HTMX form is never teleported by @vpetersson-bot in #1569
- docs: SECURITY.md names the wrong company and an SLA we do not back by @vpetersson-bot in #1565
- SIRI-52: show gated documents with a request-access gate by @vpetersson-bot in #1568
- test: add Yocto SPDX 2.2 and 3.0 sample SBOMs by @vpetersson-bot in #1573
- feat(documents): make a document's name and version unique per component by @vpetersson-bot in #1564
- chore(deps): bump the bun group across 1 directory with 14 updates by @dependabot[bot] in #1574
- feat: certification badges on the trust center by @vpetersson-bot in #1570
- fix(vulns): a CPE is an identity a VEX statement can be scoped to by @aurangzaib048 in #1572
- fix(vulns): a VEX statement we cannot apply says so by @aurangzaib048 in #1571
- feat(plugins): score the CISA 2026 minimum elements, and register the plugin by @aurangzaib048 in #1512
- feat(vulns): give a finding a row of its own by @aurangzaib048 in #1558
- SIRI-48: expose public CSAF discovery through security.txt by @vpetersson-bot in #1566
- ci: pin the one unpinned action by @vpetersson-bot in #1567
- Read every legal shape of an SPDX 3 set-valued property, and give advice that works by @aurangzaib048 in #1575
- chore(deps): bump the bun group across 1 directory with 4 updates by @dependabot[bot] in #1576
- chore(deps): bump the github-actions group across 1 directory with 4 updates by @dependabot[bot] in #1577
- compliance: pin the CRA audit logger so a raised LOG_LEVEL cannot silence it by @aurangzaib048 in #1582
- spdx3: the last two inline detectors read the shared one by @aurangzaib048 in #1584
- releases: deleting a release no longer destroys its lifecycle history by @aurangzaib048 in #1585
- billing: the limit check and the insert now share a locked transaction by @aurangzaib048 in #1587
- test: add a Yocto-scale SPDX 3.0 sample (core-image-sato-sdk, 50 MiB) by @vpetersson-bot in #1588
- uploads: make the request body ceiling reachable and configurable by @aurangzaib048 in #1590
- chore(release): 26.9.0 by @vpetersson-bot in #1591
- Enable and disable a workspace's plugins over the API by @aurangzaib048 in #1602
- Let a document be made workspace-wide from its own page by @aurangzaib048 in #1594
- Hash the Yocto fixture, so the provenance claim can fail by @aurangzaib048 in #1600
- perf(tests): a full suite run goes from ~27 minutes to 2 by @vpetersson-bot in #1604
- fix: page vulnerability findings on the server instead of rendering every row by @vpetersson-bot in #1601
- chore(deps): bump marked from 18.0.12 to 18.0.13 in the bun group by @dependabot[bot] in #1605
- Stop the log stream drowning the 500 alert by @vpetersson-bot in #1595
- One artifact ceiling, stated where it is enforced by @aurangzaib048 in #1599
- The artifact page asks for what it renders by @aurangzaib048 in #1606
- Delete a contact profile you just created by @aurangzaib048 in #1612
- chore(deps): bump the github-actions group with 2 updates by @dependabot[bot] in #1617
- chore(deps): bump the bun group across 1 directory with 10 updates by @dependabot[bot] in #1616
- Rate limit on the visitor's IP, not the Cloudflare edge by @vpetersson-bot in #1627
- Read only the page of findings a card renders by @aurangzaib048 in #1626
- Triage from the vulnerabilities panel, and choose how many rows it shows by @aurangzaib048 in #1618
- Filter and search the plugin report's findings by @aurangzaib048 in #1619
- Compile the SPDX 3 schema instead of walking its refs by @aurangzaib048 in #1620
- Run context processors once per request, not once per component by @aurangzaib048 in #1608
- Lock the workspace row while a user seat is taken by @aurangzaib048 in #1622
- Filter the full scan report, and keep its grouping by @aurangzaib048 in #1625
- Read the dashboard digest from the findings table by @aurangzaib048 in #1623
- docs: state what must never reach a public git artifact by @vpetersson-bot in #1632
- chore(deps): bump the github-actions group with 3 updates by @dependabot[bot] in #1631
- chore(deps): bump the bun group with 4 updates by @dependabot[bot] in #1630
- Render every allauth page inside the styled shell by @aurangzaib048 in #1634
- Send the access-request review link to a page, not to a section by @aurangzaib048 in #1633
- Offer the exploited-vulnerability filter only where it can match by @aurangzaib048 in #1639
- fix: three crashes reported by error tracking, and the gate that missed one by @vpetersson-bot in #1640
- docs(agents): require a diff audit before committing by @vpetersson-bot in #1642
- fix(vulns): show why every scanner skipped an SBOM by @aurangzaib048 in #1649
- Settle assessment runs that nothing will come back for by @aurangzaib048 in #1646
- chore(deps): bump the bun group with 3 updates by @dependabot[bot] in #1647
Full Changelog: v26.8.0...v26.9.0