Files
probo/cmd/probod/CHANGELOG.md
Émile Ré 95271e3f4e Release probod/v0.186.1
Signed-off-by: Émile Ré <emile@getprobo.com>
2026-05-12 14:25:20 +04:00

10 KiB

Changelog

All notable changes to probod (the server, including the bundled @probo/console, @probo/trust, and @probo/ui frontends) will be documented in this file.

Unreleased

[0.186.1] - 2026-05-12

Fixed

  • Fix wrong entity types in tracker_patterns and detected_trackers GIDs: rows carried entity types of removed CookiePatternEntityType / CookieEntityType instead of TrackerPatternEntityType / DetectedTrackerEntityType

[0.186.0] - 2026-05-12

Changed

  • Update kit package

[0.185.0] - 2026-05-12

Added

  • Add TrackerResource entity for detected scripts, iframes, images, beacons, fonts, fetches, media, and service workers, with full GraphQL, MCP, CLI, and frontend surface (list, view, create, update, delete, move-to-category); new "Resources" page under the cookie banner configuration tab
  • Add GLOB match type for tracker patterns supporting prefix, suffix, and sandwich patterns (e.g. ph_phc_*_posthog), with duration-aware merging so trackers with materially different lifetimes are no longer collapsed into a single pattern
  • Detect HTTP-header cookies via the Chromium CookieStore change event and expose a new http cookie source
  • Add tracker-type filter and color-coded badges on the trackers page for quick visual scanning across Cookie / localStorage / sessionStorage / IndexedDB / Cache Storage
  • Capture script initiator URL on detected trackers to enable per-vendor attribution for cookies and storage writes (column captured now, surfaced later)

Changed

  • Replace PREFIX tracker pattern match type with GLOB across GraphQL, MCP, and the frontend; existing PREFIX rows are migrated to GLOB with a trailing * (breaking)
  • Make tracker pattern displayName read-only across GraphQL, MCP, and the frontend — it is now derived from pattern + match type (breaking)
  • Pattern analysis worker now detects UUID-like, hash-like, and long numeric tokens as variable parts even from a single observation, so site-specific identifiers no longer get treated as static text
  • Rename the cookie banner "Detection" page to "Trackers" and drop the SCRIPT / IFRAME tracker types (replaced by TrackerResource) (breaking)
  • Agent runs now treat ctx cancellation as a graceful suspend signal: supervisor shutdown maps to run ctx cancellation, and the previous WithStopSignal API is removed (breaking for in-process callers)

Fixed

  • Fix empty country code being persisted on cookie consent records when IP geolocation returns no matching CIDR block
  • Fix SQL corruption (HTTP 500 on /report) in FindMatchingPattern caused by fmt.Sprintf interpreting % characters in the LIKE escape clause
  • Use @deleteEdge on the access review campaign delete mutation so the cached connection no longer surfaces a missing-data error when reopening the access reviews tab

[0.184.2] - 2026-05-08

Security

  • Upgrade go to 1.26.3

[0.184.1] - 2026-05-08

Changed

  • Microsoft 365 access review driver now fetches only internal members from Microsoft Graph ($filter=userType eq 'Member'), so guest (B2B) accounts are no longer pulled into access review
  • SCIM settings page now hides the other IdP connector card once a bridge is connected; both remain listed when nothing is configured

Fixed

  • Fix cookie banner opt-out button opening the preference panel instead of performing a one-click reject in OPT_OUT regulations

[0.184.0] - 2026-05-07

Added

  • Allow editing approvers inline on SOA generated documents from the Statement of Applicability detail page (visible after first publish)

Fixed

  • Fix Microsoft 365 SCIM bridge: register the MICROSOFT_365 connector provider, scope each Identity Provider card to its own bridge type so connecting one provider no longer marks others as connected, and filter Microsoft Graph users to home-tenant members (skip B2B guests)
  • Fix cookie banner REST config endpoint compatibility for SDK versions ≤ 0.2.0
  • Fix geolocation IP-to-country block imports

[0.183.0] - 2026-05-07

Added

  • Add IP-to-country geolocation service with shadow-table swap import and CIDR-based lookups
  • Detect the visitor's privacy regulation (GDPR, UK GDPR, FADP, CCPA, PIPEDA, LGPD, LFPDPPP, POPIA, PDPA, PIPL, PIPA, APPI, DPDP, PDPL) on the cookie banner config endpoint and adapt the banner UI and texts accordingly (opt-out notice for CCPA, simple notice when no regulation applies)
  • Store regulation and country code on cookie consent records and expose both across GraphQL, MCP, CLI, and n8n
  • Allow deleting access review campaigns from the UI (DRAFT or CANCELLED only, gated on core:access-review-campaign:delete)
  • Support Google Cloud Identity in the SCIM bridge (in addition to Google Workspace)

Changed

  • Access review campaigns no longer transition to FAILED when individual sources fail to fetch; the failure stays surfaced on the source fetch (status + last error) and reviewers can proceed on the sources that succeeded (breaking: removed FAILED from AccessReviewCampaignStatus)
  • Allow editing metadata (title, document type, classification) on generated document versions; only content edits remain rejected

Fixed

  • Fix cookie banner docs link to www.getprobo.com/docs

[0.182.0] - 2026-05-06

Added

  • Add Microsoft 365 SCIM bridge and access review driver
  • Add unified tracker detection backend with tracker_patterns and detected_trackers schema
  • Add trackerType field on patterns to support tracking technologies beyond cookies

Changed

  • Replace publishMajor, publishMinor, and requestDocumentVersionApproval mutations with a unified publishDocument and bulkPublishDocuments accepting minor: Boolean! and a required changelog: String! (breaking)
  • Rename cookie pattern API surfaces to tracker patterns across GraphQL, MCP, CLI, and n8n (breaking)

Removed

  • Remove legacy cookie_patterns GraphQL schema, MCP tools, CLI commands, and n8n operations

Fixed

  • Restore MCP cross-origin protection after go-sdk v1.6.0 bump

[0.181.0] - 2026-05-05

Added

  • Add SCIM tools to MCP API
  • Add SCIM commands to CLI
  • Add cookie banner detection page for uncategorised patterns
  • Add last_detected_at and last_matched_at tracking on cookie patterns
  • Add uncategorisedPatterns GraphQL connection on CookieBanner

Changed

  • Accept CIDR ranges in proxy trusted-proxies configuration
  • Rename categories to consentCategories on cookie banner API surfaces
  • Move cookie management from separate Cookies tab into the Display page
  • Filter uncategorised category from cookie banner config and version snapshots

[0.180.0] - 2026-05-04

Fixed

  • Use natural sort for SOA document export rows

Added

  • Add risk publish to document system

[0.179.1] - 2026-05-02

Fixed

  • Fix n8n cookieConsentRecord getAll operation

[0.179.0] - 2026-05-02

Added

  • Add cookie banner operations to n8n node
  • Add excluded flag to cookie patterns (GraphQL/MCP/CLI/n8n) with source badge in category table
  • Validate cookie policy link in banner description

Changed

  • Skip draft cookie banner version for uncategorised-only merges
  • Exclude uncategorised category from consent contract
  • Run cookie detection regardless of banner state
  • Stop bumping cookie banner version on no-op updates
  • Exclude translations from cookie banner version snapshots
  • Allow clearing optional fields in n8n cookie updates
  • Bump @probo/cookie-banner to 0.2.0

Fixed

  • Clear pending cookie-consent queue before stopping on 404

[0.178.0] - 2026-05-01

Added

  • Add MCP tools for cookie banner, category, pattern, version, and consent records
  • Add CLI commands for cookie banner, category, pattern, and consent records

Fixed

  • Fix auditor access to processing activities
  • Fix contract end date field cut off in Add Person dialog

[0.177.1] - 2026-04-30

Fixed

  • Reveal cookie banner sidebar entry in IAM organizations
  • Render cookie-consent placeholders when no prior consent exists
  • Fix cookie-consent placeholder sizing for absolutely or sticky positioned elements
  • Allow OIDC and magic-link sessions to assume password-only organizations

[0.177.0] - 2026-04-30

Added

  • Add cookie patterns to group detected cookies by URL prefix, with auto-detection worker and console management
  • Add DurationInput component to @probo/ui

Changed

  • Refactor cookie banner forms to react-hook-form
  • Store cookie durations as max_age_seconds
  • Update @probo/cookie-banner public exports and bump to 0.1.0

Fixed

  • Filter browser-extension cookies from detection

[0.176.1] - 2026-04-29

Fixed

  • Fix empty text nodes in generated documents

[0.176.0] - 2026-04-29

Added

  • Add vendor publish to document system, replacing snapshot mode

[0.175.0] - 2026-04-29

Added

  • Add processing activity, DPIA and TIA publish to document system, replacing snapshot mode

Changed

  • Introspect OAuth2 refresh tokens per RFC 7662, honoring token_type_hint
  • Invalidate other sessions on password change and all sessions on password reset
  • Use forwarded headers for SCIM event client IP when running behind a load balancer
  • Extract client IP from rightmost entry of X-Forwarded-For and Forwarded headers
  • Update avatar initials colors

[0.174.0] - 2026-04-28

Added

  • Add agent run supervisor with checkpoint persistence and resume across restarts
  • Add finding and obligation publish to document system, replacing snapshot mode
  • Add --state and --contract-ended filters to CLI/MCP/GraphQL user list
  • Add Notion workspace name resolver for access review
  • Add X-SDK-Version header to cookie banner SDK requests

Changed

  • Rename excludeContractEnded to contractEnded (two-way) across MCP, GraphQL, CLI, frontend
  • Remove auditor's ability to publish SoA
  • Request Google customer directory scope for access-review name sync

Fixed

  • Fix copy-paste in rich editor
  • Fix long cookie name display and label colors in cookie banner
  • Fix suspension checkpoint fallback in nested and parallel agent execution

[0.173.0] - 2026-04-27

Changed