-
released this
2026-10-02 10:24:45 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.105
Built (UTC): 2026-10-02T10:23:28Z
Source tag: v2.6.105
Image digest: sha256:ebd31ac7d44dadfdb1021920e7be60e0e1d734a9ee245166afdb10da33ccac73
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.103 (54 commits):
SCF 2026.3 — please read this one
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
the SCF Council renumbered most controls and REUSED the vacated numbers: the
control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
none of the old controls were dropped. - Upgrading refreshes the shipped catalogue on its own, with no action from
you. Your own control register does NOT move until somebody presses
Reset to SCF — until then it carries the numbering you already had. - So the order matters: upgrade, confirm the suite is running this version,
then Reset to SCF in each workspace. Run the preview first — it lists
exactly what will be deleted. If it shows evidence, applicability decisions
or control testing you want to keep, do not reset: tell us, because those
records are keyed to the old control numbers and need translating rather
than deleting. - Risks and threats are now graded per control as Likely or Possible rather
than simply mapped, so a control carries the dozen or so risks that actually
bear on it instead of nearly the whole catalogue.
Reset to SCF
- An install with its own authored policy library now gets THAT library back
after a reset. It previously restored the generic SCF documents over the
top, and nothing in the product could put the authored ones back.
Policies, standards and the control register
- The policies and standards tables drop the summary column, so several times
as many rows fit on a screen. The summary is still searchable and still on
the document; hover a name to read it. - The control register and the RACI matrix filter by SCF domain, so working
inside one domain is a single selection rather than a search term that also
matches any control mentioning it.
Elsewhere in the suite
- Cyber Risk Assessment rescales the register from 5x5 to 4x4.
- Exceptions in GRC become tabs, on both the list and the detail page.
- Cyber Advisory gains a Designs tab holding all three design documents for an
engagement — high level, detailed and data flow — and a Components tab under
Threats. A finished threat model leads with View rather than offering to run
it again, and the Word download no longer 404s.
Design history
- Each design keeps its versions. Uploading a replacement no longer displaces
the one before it: the newest is shown as current and the earlier ones
collapse behind it, each still downloadable. - Regenerating a High-Level Design keeps the generation it supersedes, marked
AI generated so it is never mistaken for a document somebody attached.
Uploaded and generated designs are numbered separately. - Versions are fixed at upload rather than counted from a position in a list,
so a version you cite in an assessment keeps pointing at the same file.
Documents that predate this carry no number rather than a misleading v1.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but