-
released this
2026-09-23 18:23:12 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.101
Built (UTC): 2026-09-23T18:21:55Z
Source tag: v2.6.101
Image digest: sha256:61d0819ba24ce2a2354c3e8ba139b214a64dad9ec6438f9ed2a032f247703fc8
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.99 (47 commits):
The threat model works end to end
The threat-modelling intake shipped inside the binary but nothing installed it,
and three faults meant that even where it was installed it could not be used.
All four are fixed, so this is the first build in which an advisor can open the
intake, answer it, record it, and get findings out.- A fresh install now carries the threat model, bound to Discovery & Assessment.
An install that already exists does not get it from seeding — apply it with
POST /api/questionnaires/threat-model, previewing first at the same path with
GET. The preview says what it would do and why, never overwrites a question
set you wrote, and refuses rather than guessing when your methodology has no
gate of that name. - Clicking "Threat Model" on the governance board now runs the wizard. It asks
one question at a time and only what your answers make relevant — 31 of the 53
for a SaaS-only system, 42 for one in public cloud. - It can be run before the project reaches Discovery & Assessment, from an entry
at the top of the board, so security architecture can see a threat model early.
Recording it does not move the project's gate. - A completed threat model raises findings. It previously raised none: the
findings endpoint could not read a questionnaire bound to a stage gate, and
reported "no findings" rather than an error.
A gate is cleared by the questionnaire being COMPLETED — the recorded decision —
rather than by every question carrying an answer. A branching set can never
satisfy the second condition, so gates behind one could not be cleared at all.Reporting and packaging
- Grafana dashboards ship inside the export, locked to the install's own
workspace, over a read-only metrics API. - One of them is the GRC exception register: what is in force, what is waiting
on a decision, what has expired or run past its decision date — and the same
exceptions broken down by theme, largest first, so a run of eleven that is
really one problem reads as one problem. - Advisory programs roll up to the workspace.
Fixes
- A seeded demonstration incident no longer reaches customer installs.
- "Record gate decision" reaches the page that records one; an advisor can sign
off a gate the AI attestation raised concerns on, with the reason recorded as
an override rather than as a clean pass.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- A fresh install now carries the threat model, bound to Discovery & Assessment.