• cyber-suite-single-tenant-v2.6.76 bd515d9278

    gandetl_admin released this 2026-09-08 18:22:12 +00:00 | 0 commits to main since this release

    Cyber Suite — single-tenant export

    Version: v2.6.76
    Built (UTC): 2026-09-08T18:11:06Z
    Source tag: v2.6.76
    Image digest: sha256:4d0309e06a6f2af72dcec89650d07db2dd63a2f6185d3f73993d7c85251771df
    Target: linux/amd64 (CGO_ENABLED=0, static)
    Provenance: binary extracted from the cosign-verified image build.yml
    published for this commit — never rebuilt here.

    Notable since v2.6.75 (0 commits):

    No functional change since the v2.6.75 export. This build exists to pick up the
    dependency and base-image fixes below.

    • golang.org/x/crypto v0.53.0 -> v0.55.0 (CVE-2026-56854, CRITICAL)
    • google.golang.org/grpc v1.82.1 -> v1.83.1 (CVE-2026-84304, HIGH)
    • The build base is now pinned by digest. The v2.6.75 export was built against a
      stale golang:1.25-alpine (go1.25.12) while production had go1.25.14, so that
      export carried seven stdlib HIGHs this one does not.
    Downloads
  • cyber-suite-single-tenant-v2.6.75 bd515d9278

    michael released this 2026-09-08 13:03:59 +00:00 | 0 commits to main since this release

    WITHDRAWN — do not deploy. Use v2.6.76.

    The cyber-suite-single-tenant.zip asset has been removed from this release on
    2026-09-08. If you already downloaded it, replace it with v2.6.76.

    Why. This build fails a HIGH/CRITICAL container scan on nine findings:

    CVE-2026-56854 golang.org/x/crypto v0.53.0 — CRITICAL
    CVE-2026-84304 google.golang.org/grpc v1.82.1 — HIGH
    7 x stdlib Go 1.25.12 — HIGH

    The first two are real dependency issues, fixed in v2.6.76 (x/crypto v0.55.0,
    grpc v1.83.1). The seven stdlib findings were an artefact of how this export was
    built: it was assembled by hand against a stale golang:1.25-alpine base
    (go1.25.12) while the production image of the same version was built on
    go1.25.14, so this zip was more vulnerable than the service it mirrors.

    What changed after this. The customer export is now built by CI from the
    same cosign-signed image as production and is never rebuilt, both image scans
    gate on HIGH/CRITICAL, and the build bases are pinned by digest. v2.6.76 is the
    first release through that pipeline and scans clean.

    The release entry is kept rather than deleted so anyone holding this zip can
    find out why it was withdrawn.

    Downloads
  • cyber-suite-single-tenant-v2.6.40 dcba90f62f

    michael released this 2026-09-01 12:12:07 +00:00 | 1 commits to main since this release

    Container delivery. Pre-built OCI image tarball inside cyber-suite-single-tenant.zip — docker load and run. Static linux/amd64 binary + Dockerfile also inside.

    Built from main a6c82d4d (go1.25, CGO_ENABLED=0, static, linux/amd64).

    Notable since v2.6.39:

    • Regulatory applicability on Vendor Control Mapping: a Required for column across ten regimes — Responsible AI, EU AI Act, SOx, GDPR, NIS2, DORA, Saudi PDPL, ISO 27001, SOC 2, NCA ECC
    • Why now carries a Regulatory relevance block: one sentence per regime, including the negatives — "why is this control not in scope for SOx" is what an auditor asks and normally what nobody has written down
    • The Microsoft agentic-AI reference set ships 780 assessments (78 controls × 10 regimes)
    • Broad baselines de-emphasised: ISO 27001 matches all 78 controls here and SOC 2 all but four, so at equal weight they drown the six regimes that actually differ
    • Sets seeded before this data existed are backfilled on next render
    • Tabbed vendor detail page; mapping table read-only with the rationale inline and SCF anchors linking into Cyber Policy
    • CSP nonce so inline scripts execute (they were silently blocked browser-side); HTML-injection fix for pages containing non-ASCII text; Temporal namespace configurable

    The Dockerfile now parameterises BASE_IMAGE, so you can wrap the same binary in your own hardened base and co-sign it — see LOAD-AND-RUN.md.


    ⚠️ Read before showing the regime data to a customer. The seeded regime determinations were derived from control text and domain, not the regulation text. They are a first pass, known to be imperfect, and on screen they look authoritative. Every entry is marked source=seed, and _meta.regimeMethodology in the seed records the provenance. Have someone who knows the regulations review them before they inform a client decision. UNASSESSED renders distinctly from NOT-REQUIRED — the product never claims a judgement nobody made.

    Downloads
  • cyber-suite-single-tenant-v2.6.39 d917a4406e

    michael released this 2026-08-27 13:38:18 +00:00 | 4 commits to main since this release

    Container delivery. Pre-built OCI image tarball inside cyber-suite-single-tenant.zip — docker load and run. Static linux/amd64 binary + Dockerfile also inside.

    Built from main 2075045 (go1.26.4, CGO_ENABLED=0, static, linux/amd64).

    Notable since v2.6.38 (30 commits):

    • Responsible-AI AI-interaction disclosure banner on every AI chat surface (ADR-0307)
    • Advisory questionnaire document extraction, citation-backed suggestions (ADR-0308)
    • Advisory tenant document-set defaults + adoption (ADR-0309)
    • Policy framework readiness scorecards from SCF mappings (ADR-0306)
    • GRC exemptions full risk-acceptance lifecycle (ADR-0305)
    • Advisory release control, assurance-gated (ADR-0160)

    Run: docker load -i cyber-suite-v2.6.39-image.tar.gz → configure setup.env (CP_SECRETS_KEY, MONGODB_URI, SINGLE_TENANT_DOMAIN) → docker run --env-file setup.env -p 8080:8080 cyber-suite:v2.6.39. See LOAD-AND-RUN.md.

    Downloads
  • cyber-suite-single-tenant-v2.6.38 d917a4406e

    michael released this 2026-08-26 14:55:27 +00:00 | 4 commits to main since this release

    Container delivery. This release ships a pre-built OCI image tarball inside
    cyber-suite-single-tenant.zip — docker load and run, no build step. The static
    linux/amd64 binary + Dockerfile are also inside if you prefer to build yourself.

    Built from main 7fa4d55 (go1.26.4, CGO_ENABLED=0, static, linux/amd64).

    Notable since v2.6.37 (270 commits):

    • Platform Backup & Restore (Azure Blob + S3-compatible, verified restore)
    • GRC: SOC 2 Trust Services Criteria pack; seven Haleon-class OTC/FMCG control packs
    • AI Security Testing plane (/aitest) Phases 1–3; Advisory AI red-team posture report + GRC evidence pack
    • Advisory: tenant-owned stage-gate board identity (ADR-0202), Validation Report overlay (ADR-0232)
    • Inventory Phase 4 continuous posture testing; Delivery portfolio Insights
    • CCA continuous control assurance collection spine
    • PII substitution for vision/OCR image egress; CI hardening (Trivy image scan, Syft SBOM, cosign)

    Run: docker load -i cyber-suite-v2.6.38-image.tar.gz → configure setup.env (CP_SECRETS_KEY, MONGODB_URI, SINGLE_TENANT_DOMAIN) → docker run --env-file setup.env -p 8080:8080 cyber-suite:v2.6.38. See LOAD-AND-RUN.md.

    Downloads
  • cyber-suite-single-tenant-v2.6.29 a3a5f67d9d

    michael released this 2026-07-22 10:34:42 +00:00 | 49 commits to main since this release

    Cyber Suite single-tenant export v2.6.29

    Built from commit ce89263ec32771c402292d3b21240c9ee4bcc3ea (ce89263) on branch main.

    Changes since v2.6.28

    • Insights PPTX branded from tenant white-label profile
    • Insights UI polish + full-register AI cluster path
    • Continues: rule + AI thematic view, bulk AI suggest, exception export

    Package

    • Asset: cyber-suite-single-tenant.zip (linux/amd64 binary + Dockerfile + setup.env.sample)
    • Container: docker build -t cyber-suite:v2.6.29 . then run with --env-file setup.env -p 8080:8080
    • Required env: CP_SECRETS_KEY

    Operator publish: FORGEJO_TOKEN=... ./publish-v2.6.29.sh

    Downloads
  • cyber-suite-single-tenant-v2.6.28 844dcab187

    michael released this 2026-07-22 09:36:16 +00:00 | 54 commits to main since this release

    Cyber Suite single-tenant export v2.6.28

    Built from commit b4c216eb4f13a69b8d7d078fca854d527396f927 (b4c216e) on branch main.

    Changes since v2.6.27

    • GRC Exception Insights: rule-based + AI thematic view (Refresh AI themes)
    • Insights PPTX / management views for board-ready decks
    • Bulk AI suggestions on the exceptions list + import-default suggest
    • Exception list export

    Package

    • Asset: cyber-suite-single-tenant.zip (linux/amd64 binary + Dockerfile + setup.env.sample)
    • Container: docker build -t cyber-suite:v2.6.28 . then run with --env-file setup.env -p 8080:8080
    • Required env: CP_SECRETS_KEY

    Operator publish: FORGEJO_TOKEN=... ./publish-v2.6.28.sh

    Downloads
  • cyber-suite-single-tenant-v2.6.27 6f965b2e19

    michael released this 2026-07-22 06:41:57 +00:00 | 59 commits to main since this release

    Cyber Suite single-tenant export v2.6.27

    Built from commit ba1f438ff8ce868812c74d0544b72c36e513ad96 (ba1f438ff8ce) on branch main.

    Changes since v2.6.26

    • SecOps ADR-0111–0114: Crisis Management (activation/lifecycle), statutory disclosure + pre-approved comms, exercise programme, Program Health KPIs
    • Inventory ADR-0081 P2: CVE version ordering (OpenSSL letters / pre-release) + derived-exposure Source/Confidence tags
    • GRC: Archer extraction cap lift (full large imports)
    • Policy: Compare Documents (library Document A + multi-file B)

    Package

    • Asset: cyber-suite-single-tenant.zip (linux/amd64 binary + Dockerfile + setup.env.sample)
    • Container: docker build -t cyber-suite:v2.6.27 . then run with --env-file setup.env -p 8080:8080
    • Required env: CP_SECRETS_KEY

    Operator publish: FORGEJO_TOKEN=... ./publish-v2.6.27.sh

    Downloads
  • cyber-suite-single-tenant-v2.6.26 5957eb9a43

    michael released this 2026-07-21 15:38:19 +00:00 | 64 commits to main since this release

    Cyber Suite single-tenant export v2.6.26

    Built from commit 285dc2dacc9746bb0e625ea276377382c144953f (285dc2dacc97) on branch main.

    Changes since v2.6.25

    • GRC ADR-0110: import dedupe/upsert by ExternalID (Archer re-import updates in place; workflow preserved)
    • Archer import: full-file import (removed silent row caps that clipped large exports)
    • Advisory ADR-0108: engagement workflow state machine + 5-day auto-close
    • Policy: mobile top-nav hamburger fix

    Package

    • Asset: cyber-suite-single-tenant.zip (linux/amd64 binary + Dockerfile + setup.env.sample)
    • Container: docker build -t cyber-suite:v2.6.26 . then run with --env-file setup.env -p 8080:8080
    • Required env: CP_SECRETS_KEY

    Operator publish: FORGEJO_TOKEN=... ./publish-v2.6.26.sh

    Downloads
  • cyber-suite-single-tenant-v2.6.25 4106e53749

    michael released this 2026-07-21 13:32:51 +00:00 | 69 commits to main since this release

    Cyber Suite single-tenant export v2.6.25

    Built from commit 52a3f2b1e031a903acdf0b1e0d7a8f3f4ef635a2 (52a3f2b1e031) on branch main.

    Changes since v2.6.24

    • GRC exception taxonomy (ADR-0104–0107): Status×Action matrix, workflow transitions + auto expire/overdue, SLA/escalation matrix, 30-pattern catalog with form auto-populate
    • RSA Archer exceptions CSV importer (deterministic)
    • Cyber Policy: policies-with-standards CSV export (Download CSV for Excel)

    Package

    • Asset: cyber-suite-single-tenant.zip (linux/amd64 binary + Dockerfile + setup.env.sample)
    • Container: docker build -t cyber-suite:v2.6.25 . then run with --env-file setup.env -p 8080:8080
    • Required env: CP_SECRETS_KEY

    Operator publish: FORGEJO_TOKEN=... ./publish-v2.6.25.sh

    Downloads