• cyber-suite-single-tenant-v2.6.101 bd515d9278

    gandetl_admin released this 2026-09-23 18:23:12 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.101
    Built (UTC): 2026-09-23T18:21:55Z
    Source tag: v2.6.101
    Image digest: sha256:61d0819ba24ce2a2354c3e8ba139b214a64dad9ec6438f9ed2a032f247703fc8
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.99 (47 commits):

    The threat model works end to end

    The threat-modelling intake shipped inside the binary but nothing installed it,
    and three faults meant that even where it was installed it could not be used.
    All four are fixed, so this is the first build in which an advisor can open the
    intake, answer it, record it, and get findings out.

    • A fresh install now carries the threat model, bound to Discovery & Assessment.
      An install that already exists does not get it from seeding — apply it with
      POST /api/questionnaires/threat-model, previewing first at the same path with
      GET. The preview says what it would do and why, never overwrites a question
      set you wrote, and refuses rather than guessing when your methodology has no
      gate of that name.
    • Clicking "Threat Model" on the governance board now runs the wizard. It asks
      one question at a time and only what your answers make relevant — 31 of the 53
      for a SaaS-only system, 42 for one in public cloud.
    • It can be run before the project reaches Discovery & Assessment, from an entry
      at the top of the board, so security architecture can see a threat model early.
      Recording it does not move the project's gate.
    • A completed threat model raises findings. It previously raised none: the
      findings endpoint could not read a questionnaire bound to a stage gate, and
      reported "no findings" rather than an error.

    A gate is cleared by the questionnaire being COMPLETED — the recorded decision —
    rather than by every question carrying an answer. A branching set can never
    satisfy the second condition, so gates behind one could not be cleared at all.

    Reporting and packaging

    • Grafana dashboards ship inside the export, locked to the install's own
      workspace, over a read-only metrics API.
    • One of them is the GRC exception register: what is in force, what is waiting
      on a decision, what has expired or run past its decision date — and the same
      exceptions broken down by theme, largest first, so a run of eleven that is
      really one problem reads as one problem.
    • Advisory programs roll up to the workspace.

    Fixes

    • A seeded demonstration incident no longer reaches customer installs.
    • "Record gate decision" reaches the page that records one; an advisor can sign
      off a gate the AI attestation raised concerns on, with the reason recorded as
      an override rather than as a clean pass.
    Downloads