-
released this
2026-09-22 12:25:31 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.100
Built (UTC): 2026-09-22T12:24:14Z
Source tag: v2.6.100
Image digest: sha256:cfec56c16642ed53c8db88eb7ed4b07e7835e9e3da2bf808588ed6cad3fa82a0
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.99 (35 commits):
Data hygiene — please upgrade
- Every export from v2.6.30 to v2.6.99 wrote a few records that did not belong
to you into your database on first start: one risk plus a risk appetite and
methodology, filed under a separate workspace. They were never visible in your
workspace, and nothing of yours was sent anywhere. This release deletes exactly
those records on its first start and logs how many it removed ("[risk] removed
N seed risk(s) ... left by an older release"). Nothing in your own workspace is touched.
Grafana dashboards (optional, off by default)
- A read-only metrics API gives Grafana your Cyber Policy, Cyber Risk Assessment
and Cyber Assurance posture: percentages and counts, never document, control or
risk content. It answers 404 until you set CYBER_SUITE_METRICS_TOKEN, and it only
ever serves your own workspace. - Three ready-made dashboards are in the new grafana/ folder of this zip, covered
by SHA256SUMS. LOAD-AND-RUN.md walks through the Infinity data source and the
import. Enable it over HTTPS only: the token is the API's only protection.
Threat model
- A fresh install now carries the Threat Model question set, bound to
"Discovery & Assessment". Previously it was compiled in but never installed. An
install that already has a threat model, or its own methodology, is left alone. - The threat-model wizard could not load, find its path or record an answer on
gates keyed by ID. It now opens, branches and records, and takes over the pane.
Exemptions (GRC)
- Draft a statement of work for an exemption, by hand or with AI assistance.
- An advisor review now sits between the AI's recommendation and management
approval: the approval gate does not open until an advisor adopts the current
recommendation, and a rejection returns the exemption to the requester. - A journey panel on each exemption shows the eight stages from intake to
completion and where it stands. - "Run AI assessment on all open exemptions" queues an assessment for every open,
unassessed exemption, with a preview of the count and a progress panel. The
exemption board also loads again: a routing bug had been hiding it.
Risk
- Board-pack KPIs (open critical / open high) now score with your own risk
methodology, as the register and reports already did. A workspace with a custom
methodology previously saw different counts in the board pack.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Every export from v2.6.30 to v2.6.99 wrote a few records that did not belong