• cyber-suite-single-tenant-v2.6.100 bd515d9278

    gandetl_admin released this 2026-09-22 12:25:31 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.100
    Built (UTC): 2026-09-22T12:24:14Z
    Source tag: v2.6.100
    Image digest: sha256:cfec56c16642ed53c8db88eb7ed4b07e7835e9e3da2bf808588ed6cad3fa82a0
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.99 (35 commits):

    Data hygiene — please upgrade

    • Every export from v2.6.30 to v2.6.99 wrote a few records that did not belong
      to you into your database on first start: one risk plus a risk appetite and
      methodology, filed under a separate workspace. They were never visible in your
      workspace, and nothing of yours was sent anywhere. This release deletes exactly
      those records on its first start and logs how many it removed ("[risk] removed
      N seed risk(s) ... left by an older release"). Nothing in your own workspace is touched.

    Grafana dashboards (optional, off by default)

    • A read-only metrics API gives Grafana your Cyber Policy, Cyber Risk Assessment
      and Cyber Assurance posture: percentages and counts, never document, control or
      risk content. It answers 404 until you set CYBER_SUITE_METRICS_TOKEN, and it only
      ever serves your own workspace.
    • Three ready-made dashboards are in the new grafana/ folder of this zip, covered
      by SHA256SUMS. LOAD-AND-RUN.md walks through the Infinity data source and the
      import. Enable it over HTTPS only: the token is the API's only protection.

    Threat model

    • A fresh install now carries the Threat Model question set, bound to
      "Discovery & Assessment". Previously it was compiled in but never installed. An
      install that already has a threat model, or its own methodology, is left alone.
    • The threat-model wizard could not load, find its path or record an answer on
      gates keyed by ID. It now opens, branches and records, and takes over the pane.

    Exemptions (GRC)

    • Draft a statement of work for an exemption, by hand or with AI assistance.
    • An advisor review now sits between the AI's recommendation and management
      approval: the approval gate does not open until an advisor adopts the current
      recommendation, and a rejection returns the exemption to the requester.
    • A journey panel on each exemption shows the eight stages from intake to
      completion and where it stands.
    • "Run AI assessment on all open exemptions" queues an assessment for every open,
      unassessed exemption, with a preview of the count and a progress panel. The
      exemption board also loads again: a routing bug had been hiding it.

    Risk

    • Board-pack KPIs (open critical / open high) now score with your own risk
      methodology, as the register and reports already did. A workspace with a custom
      methodology previously saw different counts in the board pack.
    Downloads