-
released this
2026-10-09 13:35:17 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.110
Built (UTC): 2026-10-09T13:34:09Z
Source tag: v2.6.110
Image digest: sha256:d14c37da5314405d954d6b4e03473089ddc52b95c1ea51b943a5e49c7d69bd99
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.103 (75 commits):
SCF 2026.3 — please read this one
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
the SCF Council renumbered most controls and REUSED the vacated numbers: the
control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
none of the old controls were dropped. - Upgrading refreshes the shipped catalogue on its own, with no action from
you. Your own control register does NOT move until somebody presses
Reset to SCF — until then it carries the numbering you already had. - So the order matters: upgrade, confirm the suite is running this version,
then Reset to SCF in each workspace. Run the preview first — it lists
exactly what will be deleted. If it shows evidence, applicability decisions
or control testing you want to keep, do not reset: tell us, because those
records are keyed to the old control numbers and need translating rather
than deleting. - Risks and threats are now graded per control as Likely or Possible rather
than simply mapped, so a control carries the dozen or so risks that actually
bear on it instead of nearly the whole catalogue.
Controls now carry SCF's own ranking
- Every control states the weighting SCF gives it, 1 to 10, where 10 means a
deficiency would be a material weakness to the programme. 194 of the 1,591
are material; 193 sit at 4 or below. The NIST CSF function and whether the
control bears on people, process, technology, data or facilities come with
it. - Your register picks this up when you Reset to SCF, in the same pass that
brings the new numbering. Coverage figures can then be read with weight in
mind: 82% evidenced says something quite different when the gaps are
weighted 9s and 10s.
Reset to SCF
- An install with its own authored policy library now gets THAT library back
after a reset. It previously restored the generic SCF documents over the
top, and nothing in the product could put the authored ones back. - The catalogue refresh now replaces rather than merges, which is what makes a
renumbering land cleanly, and only one process performs it — so a
deployment running more than one copy of the suite cannot half-write the
catalogue between them.
Projects
- Every project carries a Cyber profile ID — CP-2026-001 — shown before its
name. It is assigned once, never changes and is never reused, so it is safe
to quote in a report, an email or a meeting. - Share a project with /p/CP-2026-001. Whoever opens it signs in as usual and
still needs access to the workspace: the link carries no credential, it
simply lands them on the project instead of the home page. Copy link is on
the project page.
Policies, standards and the control register
- The policies and standards tables drop the summary column, so several times
as many rows fit on a screen. The summary is still searchable and still on
the document; hover a name to read it. - The control register and the RACI matrix filter by SCF domain, so working
inside one domain is a single selection rather than a search term that also
matches any control mentioning it.
Settings
- Workspace settings shows your Workspace ID, with a copy button. It is the
value the Grafana dashboards ask for as the Tenant, and the word a Reset to
SCF asks you to type. It was previously visible only as a placeholder that
disappeared once a display name was set.
Elsewhere in the suite
- Cyber Risk Assessment rescales the register from 5x5 to 4x4.
- Exceptions in GRC become tabs, on both the list and the detail page.
- Cyber Advisory gains a Design tab for the detailed design and data flow
diagram, and a Components tab under Threats. A finished threat model leads
with View rather than offering to run it again, and the Word download no
longer 404s.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
-
released this
2026-10-05 11:43:54 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.107
Built (UTC): 2026-10-05T11:42:33Z
Source tag: v2.6.107
Image digest: sha256:628b1552b6841cf9288d526995eb516e23502d9851ce1fb377547f5258c9deed
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.103 (75 commits):
SCF 2026.3 — please read this one
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
the SCF Council renumbered most controls and REUSED the vacated numbers: the
control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
none of the old controls were dropped. - Upgrading refreshes the shipped catalogue on its own, with no action from
you. Your own control register does NOT move until somebody presses
Reset to SCF — until then it carries the numbering you already had. - So the order matters: upgrade, confirm the suite is running this version,
then Reset to SCF in each workspace. Run the preview first — it lists
exactly what will be deleted. If it shows evidence, applicability decisions
or control testing you want to keep, do not reset: tell us, because those
records are keyed to the old control numbers and need translating rather
than deleting. - Risks and threats are now graded per control as Likely or Possible rather
than simply mapped, so a control carries the dozen or so risks that actually
bear on it instead of nearly the whole catalogue.
Controls now carry SCF's own ranking
- Every control states the weighting SCF gives it, 1 to 10, where 10 means a
deficiency would be a material weakness to the programme. 194 of the 1,591
are material; 193 sit at 4 or below. The NIST CSF function and whether the
control bears on people, process, technology, data or facilities come with
it. - Your register picks this up when you Reset to SCF, in the same pass that
brings the new numbering. Coverage figures can then be read with weight in
mind: 82% evidenced says something quite different when the gaps are
weighted 9s and 10s.
Reset to SCF
- An install with its own authored policy library now gets THAT library back
after a reset. It previously restored the generic SCF documents over the
top, and nothing in the product could put the authored ones back. - The catalogue refresh now replaces rather than merges, which is what makes a
renumbering land cleanly, and only one process performs it — so a
deployment running more than one copy of the suite cannot half-write the
catalogue between them.
Projects
- Every project carries a Cyber profile ID — CP-2026-001 — shown before its
name. It is assigned once, never changes and is never reused, so it is safe
to quote in a report, an email or a meeting. - Share a project with /p/CP-2026-001. Whoever opens it signs in as usual and
still needs access to the workspace: the link carries no credential, it
simply lands them on the project instead of the home page. Copy link is on
the project page.
Policies, standards and the control register
- The policies and standards tables drop the summary column, so several times
as many rows fit on a screen. The summary is still searchable and still on
the document; hover a name to read it. - The control register and the RACI matrix filter by SCF domain, so working
inside one domain is a single selection rather than a search term that also
matches any control mentioning it.
Settings
- Workspace settings shows your Workspace ID, with a copy button. It is the
value the Grafana dashboards ask for as the Tenant, and the word a Reset to
SCF asks you to type. It was previously visible only as a placeholder that
disappeared once a display name was set.
Elsewhere in the suite
- Cyber Risk Assessment rescales the register from 5x5 to 4x4.
- Exceptions in GRC become tabs, on both the list and the detail page.
- Cyber Advisory gains a Design tab for the detailed design and data flow
diagram, and a Components tab under Threats. A finished threat model leads
with View rather than offering to run it again, and the Word download no
longer 404s.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
-
released this
2026-10-02 10:24:45 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.105
Built (UTC): 2026-10-02T10:23:28Z
Source tag: v2.6.105
Image digest: sha256:ebd31ac7d44dadfdb1021920e7be60e0e1d734a9ee245166afdb10da33ccac73
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.103 (54 commits):
SCF 2026.3 — please read this one
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
the SCF Council renumbered most controls and REUSED the vacated numbers: the
control that was GOV-01 is now GOV-02, and GOV-01 now means something else.
1,534 controls become 1,591, assessment objectives 5,956 become 6,446, and
none of the old controls were dropped. - Upgrading refreshes the shipped catalogue on its own, with no action from
you. Your own control register does NOT move until somebody presses
Reset to SCF — until then it carries the numbering you already had. - So the order matters: upgrade, confirm the suite is running this version,
then Reset to SCF in each workspace. Run the preview first — it lists
exactly what will be deleted. If it shows evidence, applicability decisions
or control testing you want to keep, do not reset: tell us, because those
records are keyed to the old control numbers and need translating rather
than deleting. - Risks and threats are now graded per control as Likely or Possible rather
than simply mapped, so a control carries the dozen or so risks that actually
bear on it instead of nearly the whole catalogue.
Reset to SCF
- An install with its own authored policy library now gets THAT library back
after a reset. It previously restored the generic SCF documents over the
top, and nothing in the product could put the authored ones back.
Policies, standards and the control register
- The policies and standards tables drop the summary column, so several times
as many rows fit on a screen. The summary is still searchable and still on
the document; hover a name to read it. - The control register and the RACI matrix filter by SCF domain, so working
inside one domain is a single selection rather than a search term that also
matches any control mentioning it.
Elsewhere in the suite
- Cyber Risk Assessment rescales the register from 5x5 to 4x4.
- Exceptions in GRC become tabs, on both the list and the detail page.
- Cyber Advisory gains a Designs tab holding all three design documents for an
engagement — high level, detailed and data flow — and a Components tab under
Threats. A finished threat model leads with View rather than offering to run
it again, and the Word download no longer 404s.
Design history
- Each design keeps its versions. Uploading a replacement no longer displaces
the one before it: the newest is shown as current and the earlier ones
collapse behind it, each still downloadable. - Regenerating a High-Level Design keeps the generation it supersedes, marked
AI generated so it is never mistaken for a document somebody attached.
Uploaded and generated designs are numbered separately. - Versions are fixed at upload rather than counted from a position in a list,
so a version you cite in an assessment keeps pointing at the same file.
Documents that predate this carry no number rather than a misleading v1.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- The control catalogue moves to SCF 2026.3. The 34 domains are unchanged, but
-
released this
2026-09-30 10:40:35 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.103
Built (UTC): 2026-09-30T10:39:17Z
Source tag: v2.6.103
Image digest: sha256:c5e62301562a13444d928c87e244edd07a9af209d702126b8bf1abe04c8ef220
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.102 (35 commits):
Read this one first: the Review button on a gate questionnaire has never worked
Clicking "Review", or "Review all answers", on a gate questionnaire did
nothing at all. This affects the build you are running today.It matters more than a dead button. The review screen is the only route to
"Record the decision", and a questionnaire is not saved to the project until
that decision is recorded — the wizard says so on screen. So somebody could
answer all forty-nine questions and have no way to keep them.The cause was two functions sharing a name in one file. JavaScript silently
replaces the earlier with the later, so the questionnaire's review called the
wrong one and failed. A guard now fails the build on any repeated function
name, because nothing in the toolchain warned about it.Threats, as a place rather than a questionnaire
The threat model has produced answers since v2.6.99. It now produces a
register you can work. Every project gains a Threats tab with three views:- Threat Models — every threat model on the engagement, what has been recorded
and what is part-answered, with Resume going straight back into the
questions. A part-answered run says plainly that it lives in the browser it
was started in, because it does: nothing is on the project until the
decision is recorded. - Threats — the engagement's own threat register. Each threat carries a STRIDE
category, where it came from, an owner, a status and the controls that
address it. Threats are deliberately not scored here; an analysed threat is
scored once, as a risk, on the Risk tab, so there is never a second answer
to "how bad is this". - Trust boundaries — where something crosses between two places that trust
each other differently, with what makes each crossing strong and what does
not, side by side. Boundaries link to the threats that cross them and the
controls that defend them.
Two threat libraries to pick from
An enterprise threat library of 141 named scenarios across fifteen domains,
with typical actors, applicability triggers and MITRE ATT&CK, MITRE ATLAS and
OWASP mappings. The largest domain is agentic AI and non-human identity.
Beside it, the SCF threat catalogue's forty-one categories, natural and
man-made.They are kept as two sources on purpose. SCF names categories an enterprise
carries; the enterprise library names scenarios an attacker performs. Both are
useful and the difference matters, so every entry says which catalogue it came
from. Search covers names, scenarios, actors and technique ids — searching
T1566 finds the phishing scenarios.Picking a threat copies it into your register, where it is yours to edit. A
later version of a library never rewrites what an engagement recorded.Controls you choose, and keep
Controls can now be picked from the library by hand, for the ones no
generation run infers. A hand-picked control survives a scope sync: previously
scope sync removed anything it had not derived itself, which would have
discarded a deliberate choice.Every tenant's control library now carries the SCF control set. On an install
where it had never been populated the register was simply empty, with nothing
to scope and nothing for an assessment to count.Agentic AI assessment
Three questions it was missing, each a way a well-governed agent still leaks or
still acts on an attacker's instructions: whether retrieval is filtered to the
person asking, what is done with what the agent produces, and how a behaviour
change is caught when a model moves underneath you.Existing installs can receive them. A question set is copied into a workspace
when it is bound, so new questions in a release previously reached nobody. The
upgrade adds only questions your copy does not have, keeps your wording and
order, and touches no answer already given.Also fixed
- A control run interrupted by a restart no longer disables Generate Controls
forever. A run now reports that it is alive while it works, and one that
stops reporting is failed rather than left running indefinitely. - The severity bands on the inherent-risk view match the rest of the product:
critical at 15 and above, high at 9, medium at 4. There was previously no
critical band there at all, so a score of 20 read as "High" while the counts
beside it called the same risk critical. - The assessment report downloads as an Excel workbook as well as Word.
- "Re-run the risk profile" on the governance board lands on the triage and
says what to do, instead of opening a page and stopping.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Threat Models — every threat model on the engagement, what has been recorded
-
released this
2026-09-23 18:23:12 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.101
Built (UTC): 2026-09-23T18:21:55Z
Source tag: v2.6.101
Image digest: sha256:61d0819ba24ce2a2354c3e8ba139b214a64dad9ec6438f9ed2a032f247703fc8
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.99 (47 commits):
The threat model works end to end
The threat-modelling intake shipped inside the binary but nothing installed it,
and three faults meant that even where it was installed it could not be used.
All four are fixed, so this is the first build in which an advisor can open the
intake, answer it, record it, and get findings out.- A fresh install now carries the threat model, bound to Discovery & Assessment.
An install that already exists does not get it from seeding — apply it with
POST /api/questionnaires/threat-model, previewing first at the same path with
GET. The preview says what it would do and why, never overwrites a question
set you wrote, and refuses rather than guessing when your methodology has no
gate of that name. - Clicking "Threat Model" on the governance board now runs the wizard. It asks
one question at a time and only what your answers make relevant — 31 of the 53
for a SaaS-only system, 42 for one in public cloud. - It can be run before the project reaches Discovery & Assessment, from an entry
at the top of the board, so security architecture can see a threat model early.
Recording it does not move the project's gate. - A completed threat model raises findings. It previously raised none: the
findings endpoint could not read a questionnaire bound to a stage gate, and
reported "no findings" rather than an error.
A gate is cleared by the questionnaire being COMPLETED — the recorded decision —
rather than by every question carrying an answer. A branching set can never
satisfy the second condition, so gates behind one could not be cleared at all.Reporting and packaging
- Grafana dashboards ship inside the export, locked to the install's own
workspace, over a read-only metrics API. - One of them is the GRC exception register: what is in force, what is waiting
on a decision, what has expired or run past its decision date — and the same
exceptions broken down by theme, largest first, so a run of eleven that is
really one problem reads as one problem. - Advisory programs roll up to the workspace.
Fixes
- A seeded demonstration incident no longer reaches customer installs.
- "Record gate decision" reaches the page that records one; an advisor can sign
off a gate the AI attestation raised concerns on, with the reason recorded as
an override rather than as a clean pass.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- A fresh install now carries the threat model, bound to Discovery & Assessment.
-
released this
2026-09-22 12:25:31 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.100
Built (UTC): 2026-09-22T12:24:14Z
Source tag: v2.6.100
Image digest: sha256:cfec56c16642ed53c8db88eb7ed4b07e7835e9e3da2bf808588ed6cad3fa82a0
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.99 (35 commits):
Data hygiene — please upgrade
- Every export from v2.6.30 to v2.6.99 wrote a few records that did not belong
to you into your database on first start: one risk plus a risk appetite and
methodology, filed under a separate workspace. They were never visible in your
workspace, and nothing of yours was sent anywhere. This release deletes exactly
those records on its first start and logs how many it removed ("[risk] removed
N seed risk(s) ... left by an older release"). Nothing in your own workspace is touched.
Grafana dashboards (optional, off by default)
- A read-only metrics API gives Grafana your Cyber Policy, Cyber Risk Assessment
and Cyber Assurance posture: percentages and counts, never document, control or
risk content. It answers 404 until you set CYBER_SUITE_METRICS_TOKEN, and it only
ever serves your own workspace. - Three ready-made dashboards are in the new grafana/ folder of this zip, covered
by SHA256SUMS. LOAD-AND-RUN.md walks through the Infinity data source and the
import. Enable it over HTTPS only: the token is the API's only protection.
Threat model
- A fresh install now carries the Threat Model question set, bound to
"Discovery & Assessment". Previously it was compiled in but never installed. An
install that already has a threat model, or its own methodology, is left alone. - The threat-model wizard could not load, find its path or record an answer on
gates keyed by ID. It now opens, branches and records, and takes over the pane.
Exemptions (GRC)
- Draft a statement of work for an exemption, by hand or with AI assistance.
- An advisor review now sits between the AI's recommendation and management
approval: the approval gate does not open until an advisor adopts the current
recommendation, and a rejection returns the exemption to the requester. - A journey panel on each exemption shows the eight stages from intake to
completion and where it stands. - "Run AI assessment on all open exemptions" queues an assessment for every open,
unassessed exemption, with a preview of the count and a progress panel. The
exemption board also loads again: a routing bug had been hiding it.
Risk
- Board-pack KPIs (open critical / open high) now score with your own risk
methodology, as the register and reports already did. A workspace with a custom
methodology previously saw different counts in the board pack.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Every export from v2.6.30 to v2.6.99 wrote a few records that did not belong
-
released this
2026-09-17 15:23:05 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.99
Built (UTC): 2026-09-17T15:21:59Z
Source tag: v2.6.99
Image digest: sha256:f8348501a00d8b5076a4aee46ea4dd1cc89e3d0a5e4326cae2949d94acd53f25
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.75 (371 commits):
CORRECTION: every export from v2.6.76 to v2.6.97 repeated the v2.6.75 notes and
so told you "no functional change since the v2.6.75 export". That was wrong: the
notes are hand-written and were not replaced when those builds were cut. The work
described below has been in the product since v2.6.97 — only the description of
it is new.Cyber advisory scoping on the governance board
- A "cyber advisory only" tick box, on by default. A stage gate carries the
project-management products AND the security work; ticking the box leaves only
the documents and questions a threat model and a control gap assessment are
built from. Fifteen documents are classified in a fresh install: the thirteen
inputs plus the two deliverables. - An install that already has its documents keeps them unclassified, because
seeding only adds what is missing. Apply the shipped classification with
POST /api/document-set/classify-cyber-advisory — preview it first at
.../preview, which names what would change and what your method does not carry. - A question set is one line naming what it is. Clicking "Threat Model" runs the
intake as a wizard, one question at a time, asking only what your answers make
relevant — 31 of the 53 for a SaaS-only system, 42 for a public-cloud one.
Gate sign-off
- "Record gate decision" reaches the page that records one. It previously opened
a tab with no sign-off control on it. - An advisor can sign off a gate the AI attestation raised concerns on. The
override is recorded as an override, with the reason, never as a clean pass. - A gate is cleared by the questionnaire being COMPLETED — the recorded decision
— not by every question carrying an answer. A branching set can never reach
the second condition, so gates behind one could not be cleared at all.
Control pack and policy
- The SCF pack states obligations as MUST, and standards are named as standards
rather than as the policy above them. - Those corrections reach an install that already holds a catalogue: boot
compares a hash of the shipped pack against what is loaded and re-imports on a
mismatch, so Reset to SCF delivers the new prose.
Deployment
- A plain-HTTP deployment no longer rejects its own POSTs as cross-site. Installs
served over http were unable to save anything.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- A "cyber advisory only" tick box, on by default. A stage gate carries the
-
released this
2026-09-17 10:41:29 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.97
Built (UTC): 2026-09-17T10:39:45Z
Source tag: v2.6.97
Image digest: sha256:abe8293ed644e41e18d2b07090e2c310c91d17772027ce8af26c7728b16ea6f8
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.75 (0 commits):
No functional change since the v2.6.75 export. This build exists to pick up the
dependency and base-image fixes below.- golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
- google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
- The build base is now pinned by digest. The v2.6.75 export was built against a
stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
export carried seven stdlib HIGHs this one does not.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
released this
2026-09-16 11:55:40 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.96
Built (UTC): 2026-09-16T11:54:37Z
Source tag: v2.6.96
Image digest: sha256:dda97801a011cc8a900dbbd3a1fb08b007ff23658435d36436f5bb1f511bfb90
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.75 (0 commits):
No functional change since the v2.6.75 export. This build exists to pick up the
dependency and base-image fixes below.- golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
- google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
- The build base is now pinned by digest. The v2.6.75 export was built against a
stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
export carried seven stdlib HIGHs this one does not.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
released this
2026-09-15 22:30:30 +00:00 | 0 commits to main since this releaseCyber Suite — single-tenant export
Version: v2.6.95
Built (UTC): 2026-09-15T22:28:49Z
Source tag: v2.6.95
Image digest: sha256:9a281a1aa0675d23c7d4d870b04bd8281a112b87da3d7d2aeab85be7ad6985b8
Target: linux/amd64 (CGO_ENABLED=0, static)
Provenance: binary extracted from the cosign-verified image build.yml
published for this commit — never rebuilt here.Notable since v2.6.75 (0 commits):
No functional change since the v2.6.75 export. This build exists to pick up the
dependency and base-image fixes below.- golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
- google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
- The build base is now pinned by digest. The v2.6.75 export was built against a
stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
export carried seven stdlib HIGHs this one does not.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads