• cyber-suite-single-tenant-v2.6.110 bd515d9278

    ci-publisher released this 2026-10-09 13:35:17 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.110
    Built (UTC): 2026-10-09T13:34:09Z
    Source tag: v2.6.110
    Image digest: sha256:d14c37da5314405d954d6b4e03473089ddc52b95c1ea51b943a5e49c7d69bd99
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.103 (75 commits):

    SCF 2026.3 — please read this one

    • The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
      the SCF Council renumbered most controls and REUSED the vacated numbers: the
      control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
      1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
      none of the old controls were dropped.
    • Upgrading refreshes the shipped catalogue on its own, with no action from
      you. Your own control register does NOT move until somebody presses
      Reset to SCF — until then it carries the numbering you already had.
    • So the order matters: upgrade, confirm the suite is running this version,
      then Reset to SCF in each workspace. Run the preview first — it lists
      exactly what will be deleted. If it shows evidence, applicability decisions
      or control testing you want to keep, do not reset: tell us, because those
      records are keyed to the old control numbers and need translating rather
      than deleting.
    • Risks and threats are now graded per control as Likely or Possible rather
      than simply mapped, so a control carries the dozen or so risks that actually
      bear on it instead of nearly the whole catalogue.

    Controls now carry SCF's own ranking

    • Every control states the weighting SCF gives it, 1 to 10, where 10 means a
      deficiency would be a material weakness to the programme. 194 of the 1,591
      are material; 193 sit at 4 or below. The NIST CSF function and whether the
      control bears on people, process, technology, data or facilities come with
      it.
    • Your register picks this up when you Reset to SCF, in the same pass that
      brings the new numbering. Coverage figures can then be read with weight in
      mind: 82% evidenced says something quite different when the gaps are
      weighted 9s and 10s.

    Reset to SCF

    • An install with its own authored policy library now gets THAT library back
      after a reset. It previously restored the generic SCF documents over the
      top, and nothing in the product could put the authored ones back.
    • The catalogue refresh now replaces rather than merges, which is what makes a
      renumbering land cleanly, and only one process performs it — so a
      deployment running more than one copy of the suite cannot half-write the
      catalogue between them.

    Projects

    • Every project carries a Cyber profile ID — CP-2026-001 — shown before its
      name. It is assigned once, never changes and is never reused, so it is safe
      to quote in a report, an email or a meeting.
    • Share a project with /p/CP-2026-001. Whoever opens it signs in as usual and
      still needs access to the workspace: the link carries no credential, it
      simply lands them on the project instead of the home page. Copy link is on
      the project page.

    Policies, standards and the control register

    • The policies and standards tables drop the summary column, so several times
      as many rows fit on a screen. The summary is still searchable and still on
      the document; hover a name to read it.
    • The control register and the RACI matrix filter by SCF domain, so working
      inside one domain is a single selection rather than a search term that also
      matches any control mentioning it.

    Settings

    • Workspace settings shows your Workspace ID, with a copy button. It is the
      value the Grafana dashboards ask for as the Tenant, and the word a Reset to
      SCF asks you to type. It was previously visible only as a placeholder that
      disappeared once a display name was set.

    Elsewhere in the suite

    • Cyber Risk Assessment rescales the register from 5x5 to 4x4.
    • Exceptions in GRC become tabs, on both the list and the detail page.
    • Cyber Advisory gains a Design tab for the detailed design and data flow
      diagram, and a Components tab under Threats. A finished threat model leads
      with View rather than offering to run it again, and the Word download no
      longer 404s.
    Downloads
  • cyber-suite-single-tenant-v2.6.107 bd515d9278

    gandetl_admin released this 2026-10-05 11:43:54 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.107
    Built (UTC): 2026-10-05T11:42:33Z
    Source tag: v2.6.107
    Image digest: sha256:628b1552b6841cf9288d526995eb516e23502d9851ce1fb377547f5258c9deed
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.103 (75 commits):

    SCF 2026.3 — please read this one

    • The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
      the SCF Council renumbered most controls and REUSED the vacated numbers: the
      control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
      1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
      none of the old controls were dropped.
    • Upgrading refreshes the shipped catalogue on its own, with no action from
      you. Your own control register does NOT move until somebody presses
      Reset to SCF — until then it carries the numbering you already had.
    • So the order matters: upgrade, confirm the suite is running this version,
      then Reset to SCF in each workspace. Run the preview first — it lists
      exactly what will be deleted. If it shows evidence, applicability decisions
      or control testing you want to keep, do not reset: tell us, because those
      records are keyed to the old control numbers and need translating rather
      than deleting.
    • Risks and threats are now graded per control as Likely or Possible rather
      than simply mapped, so a control carries the dozen or so risks that actually
      bear on it instead of nearly the whole catalogue.

    Controls now carry SCF's own ranking

    • Every control states the weighting SCF gives it, 1 to 10, where 10 means a
      deficiency would be a material weakness to the programme. 194 of the 1,591
      are material; 193 sit at 4 or below. The NIST CSF function and whether the
      control bears on people, process, technology, data or facilities come with
      it.
    • Your register picks this up when you Reset to SCF, in the same pass that
      brings the new numbering. Coverage figures can then be read with weight in
      mind: 82% evidenced says something quite different when the gaps are
      weighted 9s and 10s.

    Reset to SCF

    • An install with its own authored policy library now gets THAT library back
      after a reset. It previously restored the generic SCF documents over the
      top, and nothing in the product could put the authored ones back.
    • The catalogue refresh now replaces rather than merges, which is what makes a
      renumbering land cleanly, and only one process performs it — so a
      deployment running more than one copy of the suite cannot half-write the
      catalogue between them.

    Projects

    • Every project carries a Cyber profile ID — CP-2026-001 — shown before its
      name. It is assigned once, never changes and is never reused, so it is safe
      to quote in a report, an email or a meeting.
    • Share a project with /p/CP-2026-001. Whoever opens it signs in as usual and
      still needs access to the workspace: the link carries no credential, it
      simply lands them on the project instead of the home page. Copy link is on
      the project page.

    Policies, standards and the control register

    • The policies and standards tables drop the summary column, so several times
      as many rows fit on a screen. The summary is still searchable and still on
      the document; hover a name to read it.
    • The control register and the RACI matrix filter by SCF domain, so working
      inside one domain is a single selection rather than a search term that also
      matches any control mentioning it.

    Settings

    • Workspace settings shows your Workspace ID, with a copy button. It is the
      value the Grafana dashboards ask for as the Tenant, and the word a Reset to
      SCF asks you to type. It was previously visible only as a placeholder that
      disappeared once a display name was set.

    Elsewhere in the suite

    • Cyber Risk Assessment rescales the register from 5x5 to 4x4.
    • Exceptions in GRC become tabs, on both the list and the detail page.
    • Cyber Advisory gains a Design tab for the detailed design and data flow
      diagram, and a Components tab under Threats. A finished threat model leads
      with View rather than offering to run it again, and the Word download no
      longer 404s.
    Downloads
  • cyber-suite-single-tenant-v2.6.105 bd515d9278

    gandetl_admin released this 2026-10-02 10:24:45 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.105
    Built (UTC): 2026-10-02T10:23:28Z
    Source tag: v2.6.105
    Image digest: sha256:ebd31ac7d44dadfdb1021920e7be60e0e1d734a9ee245166afdb10da33ccac73
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.103 (54 commits):

    SCF 2026.3 — please read this one

    • The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
      the SCF Council renumbered most controls and REUSED the vacated numbers: the
      control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
      1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
      none of the old controls were dropped.
    • Upgrading refreshes the shipped catalogue on its own, with no action from
      you. Your own control register does NOT move until somebody presses
      Reset to SCF — until then it carries the numbering you already had.
    • So the order matters: upgrade, confirm the suite is running this version,
      then Reset to SCF in each workspace. Run the preview first — it lists
      exactly what will be deleted. If it shows evidence, applicability decisions
      or control testing you want to keep, do not reset: tell us, because those
      records are keyed to the old control numbers and need translating rather
      than deleting.
    • Risks and threats are now graded per control as Likely or Possible rather
      than simply mapped, so a control carries the dozen or so risks that actually
      bear on it instead of nearly the whole catalogue.

    Reset to SCF

    • An install with its own authored policy library now gets THAT library back
      after a reset. It previously restored the generic SCF documents over the
      top, and nothing in the product could put the authored ones back.

    Policies, standards and the control register

    • The policies and standards tables drop the summary column, so several times
      as many rows fit on a screen. The summary is still searchable and still on
      the document; hover a name to read it.
    • The control register and the RACI matrix filter by SCF domain, so working
      inside one domain is a single selection rather than a search term that also
      matches any control mentioning it.

    Elsewhere in the suite

    • Cyber Risk Assessment rescales the register from 5x5 to 4x4.
    • Exceptions in GRC become tabs, on both the list and the detail page.
    • Cyber Advisory gains a Designs tab holding all three design documents for an
      engagement — high level, detailed and data flow — and a Components tab under
      Threats. A finished threat model leads with View rather than offering to run
      it again, and the Word download no longer 404s.

    Design history

    • Each design keeps its versions. Uploading a replacement no longer displaces
      the one before it: the newest is shown as current and the earlier ones
      collapse behind it, each still downloadable.
    • Regenerating a High-Level Design keeps the generation it supersedes, marked
      AI generated so it is never mistaken for a document somebody attached.
      Uploaded and generated designs are numbered separately.
    • Versions are fixed at upload rather than counted from a position in a list,
      so a version you cite in an assessment keeps pointing at the same file.
      Documents that predate this carry no number rather than a misleading v1.
    Downloads
  • cyber-suite-single-tenant-v2.6.103 bd515d9278

    gandetl_admin released this 2026-09-30 10:40:35 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.103
    Built (UTC): 2026-09-30T10:39:17Z
    Source tag: v2.6.103
    Image digest: sha256:c5e62301562a13444d928c87e244edd07a9af209d702126b8bf1abe04c8ef220
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.102 (35 commits):

    Read this one first: the Review button on a gate questionnaire has never worked

    Clicking "Review", or "Review all answers", on a gate questionnaire did
    nothing at all. This affects the build you are running today.

    It matters more than a dead button. The review screen is the only route to
    "Record the decision", and a questionnaire is not saved to the project until
    that decision is recorded — the wizard says so on screen. So somebody could
    answer all forty-nine questions and have no way to keep them.

    The cause was two functions sharing a name in one file. JavaScript silently
    replaces the earlier with the later, so the questionnaire's review called the
    wrong one and failed. A guard now fails the build on any repeated function
    name, because nothing in the toolchain warned about it.

    Threats, as a place rather than a questionnaire

    The threat model has produced answers since v2.6.99. It now produces a
    register you can work. Every project gains a Threats tab with three views:

    • Threat Models — every threat model on the engagement, what has been recorded
      and what is part-answered, with Resume going straight back into the
      questions. A part-answered run says plainly that it lives in the browser it
      was started in, because it does: nothing is on the project until the
      decision is recorded.
    • Threats — the engagement's own threat register. Each threat carries a STRIDE
      category, where it came from, an owner, a status and the controls that
      address it. Threats are deliberately not scored here; an analysed threat is
      scored once, as a risk, on the Risk tab, so there is never a second answer
      to "how bad is this".
    • Trust boundaries — where something crosses between two places that trust
      each other differently, with what makes each crossing strong and what does
      not, side by side. Boundaries link to the threats that cross them and the
      controls that defend them.

    Two threat libraries to pick from

    An enterprise threat library of 141 named scenarios across fifteen domains,
    with typical actors, applicability triggers and MITRE ATT&CK, MITRE ATLAS and
    OWASP mappings. The largest domain is agentic AI and non-human identity.
    Beside it, the SCF threat catalogue's forty-one categories, natural and
    man-made.

    They are kept as two sources on purpose. SCF names categories an enterprise
    carries; the enterprise library names scenarios an attacker performs. Both are
    useful and the difference matters, so every entry says which catalogue it came
    from. Search covers names, scenarios, actors and technique ids — searching
    T1566 finds the phishing scenarios.

    Picking a threat copies it into your register, where it is yours to edit. A
    later version of a library never rewrites what an engagement recorded.

    Controls you choose, and keep

    Controls can now be picked from the library by hand, for the ones no
    generation run infers. A hand-picked control survives a scope sync: previously
    scope sync removed anything it had not derived itself, which would have
    discarded a deliberate choice.

    Every tenant's control library now carries the SCF control set. On an install
    where it had never been populated the register was simply empty, with nothing
    to scope and nothing for an assessment to count.

    Agentic AI assessment

    Three questions it was missing, each a way a well-governed agent still leaks or
    still acts on an attacker's instructions: whether retrieval is filtered to the
    person asking, what is done with what the agent produces, and how a behaviour
    change is caught when a model moves underneath you.

    Existing installs can receive them. A question set is copied into a workspace
    when it is bound, so new questions in a release previously reached nobody. The
    upgrade adds only questions your copy does not have, keeps your wording and
    order, and touches no answer already given.

    Also fixed

    • A control run interrupted by a restart no longer disables Generate Controls
      forever. A run now reports that it is alive while it works, and one that
      stops reporting is failed rather than left running indefinitely.
    • The severity bands on the inherent-risk view match the rest of the product:
      critical at 15 and above, high at 9, medium at 4. There was previously no
      critical band there at all, so a score of 20 read as "High" while the counts
      beside it called the same risk critical.
    • The assessment report downloads as an Excel workbook as well as Word.
    • "Re-run the risk profile" on the governance board lands on the triage and
      says what to do, instead of opening a page and stopping.
    Downloads
  • cyber-suite-single-tenant-v2.6.101 bd515d9278

    gandetl_admin released this 2026-09-23 18:23:12 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.101
    Built (UTC): 2026-09-23T18:21:55Z
    Source tag: v2.6.101
    Image digest: sha256:61d0819ba24ce2a2354c3e8ba139b214a64dad9ec6438f9ed2a032f247703fc8
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.99 (47 commits):

    The threat model works end to end

    The threat-modelling intake shipped inside the binary but nothing installed it,
    and three faults meant that even where it was installed it could not be used.
    All four are fixed, so this is the first build in which an advisor can open the
    intake, answer it, record it, and get findings out.

    • A fresh install now carries the threat model, bound to Discovery & Assessment.
      An install that already exists does not get it from seeding — apply it with
      POST /api/questionnaires/threat-model, previewing first at the same path with
      GET. The preview says what it would do and why, never overwrites a question
      set you wrote, and refuses rather than guessing when your methodology has no
      gate of that name.
    • Clicking "Threat Model" on the governance board now runs the wizard. It asks
      one question at a time and only what your answers make relevant — 31 of the 53
      for a SaaS-only system, 42 for one in public cloud.
    • It can be run before the project reaches Discovery & Assessment, from an entry
      at the top of the board, so security architecture can see a threat model early.
      Recording it does not move the project's gate.
    • A completed threat model raises findings. It previously raised none: the
      findings endpoint could not read a questionnaire bound to a stage gate, and
      reported "no findings" rather than an error.

    A gate is cleared by the questionnaire being COMPLETED — the recorded decision —
    rather than by every question carrying an answer. A branching set can never
    satisfy the second condition, so gates behind one could not be cleared at all.

    Reporting and packaging

    • Grafana dashboards ship inside the export, locked to the install's own
      workspace, over a read-only metrics API.
    • One of them is the GRC exception register: what is in force, what is waiting
      on a decision, what has expired or run past its decision date — and the same
      exceptions broken down by theme, largest first, so a run of eleven that is
      really one problem reads as one problem.
    • Advisory programs roll up to the workspace.

    Fixes

    • A seeded demonstration incident no longer reaches customer installs.
    • "Record gate decision" reaches the page that records one; an advisor can sign
      off a gate the AI attestation raised concerns on, with the reason recorded as
      an override rather than as a clean pass.
    Downloads
  • cyber-suite-single-tenant-v2.6.100 bd515d9278

    gandetl_admin released this 2026-09-22 12:25:31 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.100
    Built (UTC): 2026-09-22T12:24:14Z
    Source tag: v2.6.100
    Image digest: sha256:cfec56c16642ed53c8db88eb7ed4b07e7835e9e3da2bf808588ed6cad3fa82a0
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.99 (35 commits):

    Data hygiene — please upgrade

    • Every export from v2.6.30 to v2.6.99 wrote a few records that did not belong
      to you into your database on first start: one risk plus a risk appetite and
      methodology, filed under a separate workspace. They were never visible in your
      workspace, and nothing of yours was sent anywhere. This release deletes exactly
      those records on its first start and logs how many it removed ("[risk] removed
      N seed risk(s) ... left by an older release"). Nothing in your own workspace is touched.

    Grafana dashboards (optional, off by default)

    • A read-only metrics API gives Grafana your Cyber Policy, Cyber Risk Assessment
      and Cyber Assurance posture: percentages and counts, never document, control or
      risk content. It answers 404 until you set CYBER_SUITE_METRICS_TOKEN, and it only
      ever serves your own workspace.
    • Three ready-made dashboards are in the new grafana/ folder of this zip, covered
      by SHA256SUMS. LOAD-AND-RUN.md walks through the Infinity data source and the
      import. Enable it over HTTPS only: the token is the API's only protection.

    Threat model

    • A fresh install now carries the Threat Model question set, bound to
      "Discovery & Assessment". Previously it was compiled in but never installed. An
      install that already has a threat model, or its own methodology, is left alone.
    • The threat-model wizard could not load, find its path or record an answer on
      gates keyed by ID. It now opens, branches and records, and takes over the pane.

    Exemptions (GRC)

    • Draft a statement of work for an exemption, by hand or with AI assistance.
    • An advisor review now sits between the AI's recommendation and management
      approval: the approval gate does not open until an advisor adopts the current
      recommendation, and a rejection returns the exemption to the requester.
    • A journey panel on each exemption shows the eight stages from intake to
      completion and where it stands.
    • "Run AI assessment on all open exemptions" queues an assessment for every open,
      unassessed exemption, with a preview of the count and a progress panel. The
      exemption board also loads again: a routing bug had been hiding it.

    Risk

    • Board-pack KPIs (open critical / open high) now score with your own risk
      methodology, as the register and reports already did. A workspace with a custom
      methodology previously saw different counts in the board pack.
    Downloads
  • cyber-suite-single-tenant-v2.6.99 bd515d9278

    gandetl_admin released this 2026-09-17 15:23:05 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.99
    Built (UTC): 2026-09-17T15:21:59Z
    Source tag: v2.6.99
    Image digest: sha256:f8348501a00d8b5076a4aee46ea4dd1cc89e3d0a5e4326cae2949d94acd53f25
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.75 (371 commits):

    CORRECTION: every export from v2.6.76 to v2.6.97 repeated the v2.6.75 notes and
    so told you "no functional change since the v2.6.75 export". That was wrong: the
    notes are hand-written and were not replaced when those builds were cut. The work
    described below has been in the product since v2.6.97 — only the description of
    it is new.

    Cyber advisory scoping on the governance board

    • A "cyber advisory only" tick box, on by default. A stage gate carries the
      project-management products AND the security work; ticking the box leaves only
      the documents and questions a threat model and a control gap assessment are
      built from. Fifteen documents are classified in a fresh install: the thirteen
      inputs plus the two deliverables.
    • An install that already has its documents keeps them unclassified, because
      seeding only adds what is missing. Apply the shipped classification with
      POST /api/document-set/classify-cyber-advisory — preview it first at
      .../preview, which names what would change and what your method does not carry.
    • A question set is one line naming what it is. Clicking "Threat Model" runs the
      intake as a wizard, one question at a time, asking only what your answers make
      relevant — 31 of the 53 for a SaaS-only system, 42 for a public-cloud one.

    Gate sign-off

    • "Record gate decision" reaches the page that records one. It previously opened
      a tab with no sign-off control on it.
    • An advisor can sign off a gate the AI attestation raised concerns on. The
      override is recorded as an override, with the reason, never as a clean pass.
    • A gate is cleared by the questionnaire being COMPLETED — the recorded decision
      — not by every question carrying an answer. A branching set can never reach
      the second condition, so gates behind one could not be cleared at all.

    Control pack and policy

    • The SCF pack states obligations as MUST, and standards are named as standards
      rather than as the policy above them.
    • Those corrections reach an install that already holds a catalogue: boot
      compares a hash of the shipped pack against what is loaded and re-imports on a
      mismatch, so Reset to SCF delivers the new prose.

    Deployment

    • A plain-HTTP deployment no longer rejects its own POSTs as cross-site. Installs
      served over http were unable to save anything.
    Downloads
  • cyber-suite-single-tenant-v2.6.97 bd515d9278

    gandetl_admin released this 2026-09-17 10:41:29 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.97
    Built (UTC): 2026-09-17T10:39:45Z
    Source tag: v2.6.97
    Image digest: sha256:abe8293ed644e41e18d2b07090e2c310c91d17772027ce8af26c7728b16ea6f8
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.75 (0 commits):

    No functional change since the v2.6.75 export. This build exists to pick up the
    dependency and base-image fixes below.

    • golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
    • google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
    • The build base is now pinned by digest. The v2.6.75 export was built against a
      stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
      export carried seven stdlib HIGHs this one does not.
    Downloads
  • cyber-suite-single-tenant-v2.6.96 bd515d9278

    gandetl_admin released this 2026-09-16 11:55:40 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.96
    Built (UTC): 2026-09-16T11:54:37Z
    Source tag: v2.6.96
    Image digest: sha256:dda97801a011cc8a900dbbd3a1fb08b007ff23658435d36436f5bb1f511bfb90
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.75 (0 commits):

    No functional change since the v2.6.75 export. This build exists to pick up the
    dependency and base-image fixes below.

    • golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
    • google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
    • The build base is now pinned by digest. The v2.6.75 export was built against a
      stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
      export carried seven stdlib HIGHs this one does not.
    Downloads
  • cyber-suite-single-tenant-v2.6.95 bd515d9278

    gandetl_admin released this 2026-09-15 22:30:30 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.95
    Built (UTC): 2026-09-15T22:28:49Z
    Source tag: v2.6.95
    Image digest: sha256:9a281a1aa0675d23c7d4d870b04bd8281a112b87da3d7d2aeab85be7ad6985b8
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.75 (0 commits):

    No functional change since the v2.6.75 export. This build exists to pick up the
    dependency and base-image fixes below.

    • golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
    • google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
    • The build base is now pinned by digest. The v2.6.75 export was built against a
      stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
      export carried seven stdlib HIGHs this one does not.
    Downloads