• cyber-suite-single-tenant-v2.6.99 bd515d9278

    gandetl_admin released this 2026-09-17 15:23:05 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.99
    Built (UTC): 2026-09-17T15:21:59Z
    Source tag: v2.6.99
    Image digest: sha256:f8348501a00d8b5076a4aee46ea4dd1cc89e3d0a5e4326cae2949d94acd53f25
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.75 (371 commits):

    CORRECTION: every export from v2.6.76 to v2.6.97 repeated the v2.6.75 notes and
    so told you "no functional change since the v2.6.75 export". That was wrong: the
    notes are hand-written and were not replaced when those builds were cut. The work
    described below has been in the product since v2.6.97 — only the description of
    it is new.

    Cyber advisory scoping on the governance board

    • A "cyber advisory only" tick box, on by default. A stage gate carries the
      project-management products AND the security work; ticking the box leaves only
      the documents and questions a threat model and a control gap assessment are
      built from. Fifteen documents are classified in a fresh install: the thirteen
      inputs plus the two deliverables.
    • An install that already has its documents keeps them unclassified, because
      seeding only adds what is missing. Apply the shipped classification with
      POST /api/document-set/classify-cyber-advisory — preview it first at
      .../preview, which names what would change and what your method does not carry.
    • A question set is one line naming what it is. Clicking "Threat Model" runs the
      intake as a wizard, one question at a time, asking only what your answers make
      relevant — 31 of the 53 for a SaaS-only system, 42 for a public-cloud one.

    Gate sign-off

    • "Record gate decision" reaches the page that records one. It previously opened
      a tab with no sign-off control on it.
    • An advisor can sign off a gate the AI attestation raised concerns on. The
      override is recorded as an override, with the reason, never as a clean pass.
    • A gate is cleared by the questionnaire being COMPLETED — the recorded decision
      — not by every question carrying an answer. A branching set can never reach
      the second condition, so gates behind one could not be cleared at all.

    Control pack and policy

    • The SCF pack states obligations as MUST, and standards are named as standards
      rather than as the policy above them.
    • Those corrections reach an install that already holds a catalogue: boot
      compares a hash of the shipped pack against what is loaded and re-imports on a
      mismatch, so Reset to SCF delivers the new prose.

    Deployment

    • A plain-HTTP deployment no longer rejects its own POSTs as cross-site. Installs
      served over http were unable to save anything.
    Downloads