4.9 KiB
4.9 KiB
Changelog
All notable changes to this project will be documented in this file.
[Unreleased]
Added
- Added vendors.json data file under Creative Commons Attribution-ShareAlike 4.0 license`
- New vendor data management system with comprehensive vendor information
- Pre-populated vendor database with 12 common SaaS vendors and their certifications
- Vendor details page with extended fields for improved vendor management:
- Legal name and headquarters address
- Website URL
- Certification tracking with tag-based interface
- Links to important vendor documents (SLA, DPA, security pages)
- Support for multiple compliance certifications per vendor
Fixed
- Fix cannot create vendor when the name is too similar to suggested one
- Fix UI showing double button to close evidence preview modal
- Fix cannot delete vendor with compliance reports (added cascade delete constraint)
[0.5.0] - 2025-04-10
Added
- Add vendor compliance reports UI
- Controls can now be linked to policies, enabling better organization of compliance documentation and clearer traceability between policies and security controls
- New UI for viewing and managing policies related to a specific control
[0.4.2] - 2025-04-09
Changed
- Simplified policy data model by removing version field and optimistic concurrency
- Refactored policy update flow to load-modify-save pattern
Fixed
- Added user-friendly error messages when importing frameworks that already exist
[0.4.1] - 2025-04-09
Changed
- Update ISO 27001 and SOC2 framework definition.
[0.4.0] - 2025-04-09
BREAKING CHANGES
- BREAKING: Renamed GraphQL mutations for control-mitigation mappings:
createControlMapping→createControlMitigationMappingdeleteControlMapping→deleteControlMitigationMapping- Input and payload types have been updated accordingly
Added
- Add import control <> mitigation mapping.
- Add mitigation tasks import.
- Add auto-scroll to opened category.
- Added support for mapping controls to policies:
- New GraphQL mutations
createControlPolicyMappinganddeleteControlPolicyMapping - Controls can now be associated with both mitigations and policies
- New bidirectional relationships:
- Control objects now expose a
policiesfield to list associated policies - Policy objects now expose a
controlsfield to list associated controls
- Control objects now expose a
- New GraphQL mutations
- Added vendor compliance reports:
- New GraphQL types
VendorComplianceReportand related connection types - New GraphQL mutations
uploadVendorComplianceReportanddeleteVendorComplianceReport - New
complianceReportsfield on the Vendor type - Support for uploading, viewing, and managing vendor compliance documentation
- New GraphQL types
- Added pre-configured frameworks:
- Added ISO/IEC 27001:2022 and SOC 2 framework templates
- Improved framework import interface with dropdown menu for template selection
- Support for one-click import of standard compliance frameworks
Changed
- Evidence can now be requested.
Fixed
- Fix unfoldable mitigation category when open via the URI fragment.
- Fix ctrl+click on mitigation does not open new tab.
- Fix error handling in framework view when no controls are available.
[0.3.0] - 2025-04-01
Added
- Add sidebar to show a task.
- Add task estimate edition.
- Add control+framework auditor views.
- Add import mitigations support.
- Add import framework support.
- Add risk object management.
- Add risk template.
- Add mapping between control and risk.
Changed
- Rename control in mitigation.
- Home page is now mitigations page.
Fixed
- Fix panic in GraphQL resolver are not reported.
- Fix otal trace never started.
- Fix React.lazy chunck error.
- Fix login page show
unauthorizederror. - Fix cannot delete task with evidences.
- Fix cannot download file with non-ASCII filename.
[0.2.0] - 2025-03-24
Added
- Add forget password.
- Allow evidence to be a link.
- Add task import support.
- Allow to create vendor when it not exist in the auto-complete.
- Add service account people kind.
Changed
- Make task time estimate optional.
- Set invitation token to 12 hours.
- Order people by fullname.
- Order vendor by name.
- Allow to edit control state without going to edit page.
- Redirect on people list after people creation.
- New UI for the framework overview page.
Fixed
- Fix flickering on hover on categories.
- Fix control order under a category.
- Fix UI does not refresh after importing a framework.
- Fix cannot create control.
- Fix missing include cookie on confirmation invit.
- Fix sign-in does not include cookie.
- Fix missing version when create task.
- Fix random order on framework overview.
- Fix change task state not visible on UI.
- Fix control card items alignement.
- Fix cannot delete task.
- Fix password managers misidentifying token fields as usernames in reset password and invitation confirmation forms.
[0.1.0] - 2025-03-14
Initial release.