14 KiB
14 KiB
Changelog
All notable changes to probod (the server, including the bundled @probo/console, @probo/trust, and @probo/ui frontends) will be documented in this file.
Unreleased
[0.190.0] - 2026-05-20
Added
- Add a hierarchical risk assessment system with Risk Assessment, Scope, Node (ENTITY / BOUNDARY / ASSET / DATA), Process, Threat, and Risk Scenario entities, and render a Mermaid data-flow diagram per scope (nodes typed by shape, threats attached as dashed edges)
- Add 13 access-review connector providers (with PKCE, token-body extras, and
AuthURLtemplating support in the OAuth2 driver), and wire them through the review engine, the name worker, and the Helm chart - Add a tracker mapping worker that resolves detected trackers to third parties using initiator domain extraction (eTLD+1), pattern-glob analysis, and a Firecrawl-backed LLM agent fallback for unmapped patterns
- Add a shared
common_third_parties/common_third_party_domainscatalog with slug-based deduplication, allow a single domain to be associated with multiple third parties, and auto-create entries from OCD imports - Introduce the
proboctlCLI (replaces the standalonecommon-third-parties-importandcommon-tracker-patterns-importcommands asproboctl seed ...), withdata.jsonembedded in the binary
Changed
- Move the Firecrawl API key from the top-level config into
Agents.Tools, hardcode the Firecrawl API endpoint (dropFIRECRAWL_ENDPOINT), and replace the SearXNG search backend with Firecrawl - Split cookie names on both
_and-separators so cookies like__Secure-1PSIDno longer collapse into a bogus___*heuristic pattern
Fixed
- Filter SCIM-deactivated (INACTIVE) people from signature request recipient lists in both the multi-select dialog and the document signatures page
Removed
- Remove the deprecated snapshot system (the register/document model fully replaces it)
- Remove backend inactive-profile validation that incorrectly rejected newly-created users on first login
[0.189.0] - 2026-05-15
Changed
- Rename
vendortothird partyacross the API surface (GraphQL, MCP), database schema (migration), webhook event types (vendor:*→third_party:*), snapshot type (VENDORS→THIRD_PARTIES), and console / trust URL paths (breaking) - Log
identity_idon every authenticated request (cookie session, API key, OAuth2 access token) so operators can correlate a request back to its user and credential
[0.188.0] - 2026-05-13
Changed
- Derive cookie consent mode dynamically from the visitor's country and applicable regulation at consent-recording time; the
consent_modecolumn is dropped fromcookie_bannersand persisted oncookie_consent_recordsinstead, defaulting toOPT_OUTwhen no regulation matches (breaking) - Capture
X-SDK-Versionvia middleware and include it assdk_versionon all cookie banner request logs - Use distinct badge colors per resource type and tracker type instead of only highlighting scripts
Fixed
- Eliminate deadlocks when concurrent
ReportDetectedTrackerscalls updatetracker_patterns.last_matched_atby replacing per-row updates with a single bulk update - Stop generating bare
*tracker patterns from separator-less cookie names; such names are kept as individual exact-match patterns for triage
Removed
- Drop the legacy
cookiesandcookie_patternstables (superseded bytracker_patternsanddetected_trackers)
[0.187.0] - 2026-05-12
Added
- Add a shared
common_third_partiesreference catalog, seeded frompackages/vendors/data.jsonvia a one-shotcommon-third-parties-importCLI, and back theCreateVendorDialogautocomplete with a newcommonThirdParties(name)GraphQL query (server-sideILIKEsearch) instead of shipping the full vendor JSON bundle to the browser - Self-host vendor logos in S3: at import time, fetch each site's HTML and pick the best icon (SVG,
apple-touch-icon, large PNG,msapplication-TileImage) via the newpkg/webinspectpackage, then serve through the existing/api/files/v1/{id}endpoint instead of calling Google's favicon service per page load
Changed
- Sanitize MCP error responses so internal details (stack traces, wrapped errors) are no longer leaked to clients
Fixed
- Return a clean not-found error instead of a 500 when a membership lookup misses
- Upgrade
mermaidto 11.15.0 to address GHSA-6m6c-36f7-fhxh (Gantt infinite-loop DoS), GHSA-xcj9-5m2h-648r and GHSA-87f9-hvmw-gh4p (CSS injection viaclassDef/configuration), and GHSA-ghcm-xqfw-q4vr (HTML injection viaclassDefin state diagrams)
[0.186.1] - 2026-05-12
Fixed
- Fix wrong entity types in
tracker_patternsanddetected_trackersGIDs: rows carried entity types of removedCookiePatternEntityType/CookieEntityTypeinstead ofTrackerPatternEntityType/DetectedTrackerEntityType
[0.186.0] - 2026-05-12
Changed
- Update kit package
[0.185.0] - 2026-05-12
Added
- Add
TrackerResourceentity for detected scripts, iframes, images, beacons, fonts, fetches, media, and service workers, with full GraphQL, MCP, CLI, and frontend surface (list, view, create, update, delete, move-to-category); new "Resources" page under the cookie banner configuration tab - Add
GLOBmatch type for tracker patterns supporting prefix, suffix, and sandwich patterns (e.g.ph_phc_*_posthog), with duration-aware merging so trackers with materially different lifetimes are no longer collapsed into a single pattern - Detect HTTP-header cookies via the Chromium
CookieStorechange event and expose a newhttpcookie source - Add tracker-type filter and color-coded badges on the trackers page for quick visual scanning across Cookie / localStorage / sessionStorage / IndexedDB / Cache Storage
- Capture script initiator URL on detected trackers to enable per-vendor attribution for cookies and storage writes (column captured now, surfaced later)
Changed
- Replace
PREFIXtracker pattern match type withGLOBacross GraphQL, MCP, and the frontend; existingPREFIXrows are migrated toGLOBwith a trailing*(breaking) - Make tracker pattern
displayNameread-only across GraphQL, MCP, and the frontend — it is now derived from pattern + match type (breaking) - Pattern analysis worker now detects UUID-like, hash-like, and long numeric tokens as variable parts even from a single observation, so site-specific identifiers no longer get treated as static text
- Rename the cookie banner "Detection" page to "Trackers" and drop the
SCRIPT/IFRAMEtracker types (replaced byTrackerResource) (breaking) - Agent runs now treat ctx cancellation as a graceful suspend signal: supervisor shutdown maps to run ctx cancellation, and the previous
WithStopSignalAPI is removed (breaking for in-process callers)
Fixed
- Fix empty country code being persisted on cookie consent records when IP geolocation returns no matching CIDR block
- Fix SQL corruption (HTTP 500 on
/report) inFindMatchingPatterncaused byfmt.Sprintfinterpreting%characters in the LIKE escape clause - Use
@deleteEdgeon the access review campaign delete mutation so the cached connection no longer surfaces a missing-data error when reopening the access reviews tab
[0.184.2] - 2026-05-08
Security
- Upgrade go to 1.26.3
[0.184.1] - 2026-05-08
Changed
- Microsoft 365 access review driver now fetches only internal members from Microsoft Graph (
$filter=userType eq 'Member'), so guest (B2B) accounts are no longer pulled into access review - SCIM settings page now hides the other IdP connector card once a bridge is connected; both remain listed when nothing is configured
Fixed
- Fix cookie banner opt-out button opening the preference panel instead of performing a one-click reject in OPT_OUT regulations
[0.184.0] - 2026-05-07
Added
- Allow editing approvers inline on SOA generated documents from the Statement of Applicability detail page (visible after first publish)
Fixed
- Fix Microsoft 365 SCIM bridge: register the
MICROSOFT_365connector provider, scope each Identity Provider card to its own bridge type so connecting one provider no longer marks others as connected, and filter Microsoft Graph users to home-tenant members (skip B2B guests) - Fix cookie banner REST config endpoint compatibility for SDK versions ≤ 0.2.0
- Fix geolocation IP-to-country block imports
[0.183.0] - 2026-05-07
Added
- Add IP-to-country geolocation service with shadow-table swap import and CIDR-based lookups
- Detect the visitor's privacy regulation (GDPR, UK GDPR, FADP, CCPA, PIPEDA, LGPD, LFPDPPP, POPIA, PDPA, PIPL, PIPA, APPI, DPDP, PDPL) on the cookie banner config endpoint and adapt the banner UI and texts accordingly (opt-out notice for CCPA, simple notice when no regulation applies)
- Store regulation and country code on cookie consent records and expose both across GraphQL, MCP, CLI, and n8n
- Allow deleting access review campaigns from the UI (DRAFT or CANCELLED only, gated on
core:access-review-campaign:delete) - Support Google Cloud Identity in the SCIM bridge (in addition to Google Workspace)
Changed
- Access review campaigns no longer transition to
FAILEDwhen individual sources fail to fetch; the failure stays surfaced on the source fetch (status + last error) and reviewers can proceed on the sources that succeeded (breaking: removedFAILEDfromAccessReviewCampaignStatus) - Allow editing metadata (title, document type, classification) on generated document versions; only content edits remain rejected
Fixed
- Fix cookie banner docs link to
www.getprobo.com/docs
[0.182.0] - 2026-05-06
Added
- Add Microsoft 365 SCIM bridge and access review driver
- Add unified tracker detection backend with
tracker_patternsanddetected_trackersschema - Add
trackerTypefield on patterns to support tracking technologies beyond cookies
Changed
- Replace
publishMajor,publishMinor, andrequestDocumentVersionApprovalmutations with a unifiedpublishDocumentandbulkPublishDocumentsacceptingminor: Boolean!and a requiredchangelog: String!(breaking) - Rename cookie pattern API surfaces to tracker patterns across GraphQL, MCP, CLI, and n8n (breaking)
Removed
- Remove legacy
cookie_patternsGraphQL schema, MCP tools, CLI commands, and n8n operations
Fixed
- Restore MCP cross-origin protection after go-sdk v1.6.0 bump
[0.181.0] - 2026-05-05
Added
- Add SCIM tools to MCP API
- Add SCIM commands to CLI
- Add cookie banner detection page for uncategorised patterns
- Add
last_detected_atandlast_matched_attracking on cookie patterns - Add
uncategorisedPatternsGraphQL connection onCookieBanner
Changed
- Accept CIDR ranges in proxy
trusted-proxiesconfiguration - Rename
categoriestoconsentCategorieson cookie banner API surfaces - Move cookie management from separate Cookies tab into the Display page
- Filter uncategorised category from cookie banner config and version snapshots
[0.180.0] - 2026-05-04
Fixed
- Use natural sort for SOA document export rows
Added
- Add risk publish to document system
[0.179.1] - 2026-05-02
Fixed
- Fix n8n cookieConsentRecord getAll operation
[0.179.0] - 2026-05-02
Added
- Add cookie banner operations to n8n node
- Add
excludedflag to cookie patterns (GraphQL/MCP/CLI/n8n) with source badge in category table - Validate cookie policy link in banner description
Changed
- Skip draft cookie banner version for uncategorised-only merges
- Exclude uncategorised category from consent contract
- Run cookie detection regardless of banner state
- Stop bumping cookie banner version on no-op updates
- Exclude translations from cookie banner version snapshots
- Allow clearing optional fields in n8n cookie updates
- Bump
@probo/cookie-bannerto 0.2.0
Fixed
- Clear pending cookie-consent queue before stopping on 404
[0.178.0] - 2026-05-01
Added
- Add MCP tools for cookie banner, category, pattern, version, and consent records
- Add CLI commands for cookie banner, category, pattern, and consent records
Fixed
- Fix auditor access to processing activities
- Fix contract end date field cut off in Add Person dialog
[0.177.1] - 2026-04-30
Fixed
- Reveal cookie banner sidebar entry in IAM organizations
- Render cookie-consent placeholders when no prior consent exists
- Fix cookie-consent placeholder sizing for absolutely or sticky positioned elements
- Allow OIDC and magic-link sessions to assume password-only organizations
[0.177.0] - 2026-04-30
Added
- Add cookie patterns to group detected cookies by URL prefix, with auto-detection worker and console management
- Add
DurationInputcomponent to@probo/ui
Changed
- Refactor cookie banner forms to react-hook-form
- Store cookie durations as
max_age_seconds - Update
@probo/cookie-bannerpublic exports and bump to 0.1.0
Fixed
- Filter browser-extension cookies from detection
[0.176.1] - 2026-04-29
Fixed
- Fix empty text nodes in generated documents
[0.176.0] - 2026-04-29
Added
- Add vendor publish to document system, replacing snapshot mode
[0.175.0] - 2026-04-29
Added
- Add processing activity, DPIA and TIA publish to document system, replacing snapshot mode
Changed
- Introspect OAuth2 refresh tokens per RFC 7662, honoring
token_type_hint - Invalidate other sessions on password change and all sessions on password reset
- Use forwarded headers for SCIM event client IP when running behind a load balancer
- Extract client IP from rightmost entry of
X-Forwarded-ForandForwardedheaders - Update avatar initials colors
[0.174.0] - 2026-04-28
Added
- Add agent run supervisor with checkpoint persistence and resume across restarts
- Add finding and obligation publish to document system, replacing snapshot mode
- Add
--stateand--contract-endedfilters to CLI/MCP/GraphQL user list - Add Notion workspace name resolver for access review
- Add
X-SDK-Versionheader to cookie banner SDK requests
Changed
- Rename
excludeContractEndedtocontractEnded(two-way) across MCP, GraphQL, CLI, frontend - Remove auditor's ability to publish SoA
- Request Google customer directory scope for access-review name sync
Fixed
- Fix copy-paste in rich editor
- Fix long cookie name display and label colors in cookie banner
- Fix suspension checkpoint fallback in nested and parallel agent execution
[0.173.0] - 2026-04-27
Changed
- First per-package release. Prior history is in the archived monorepo CHANGELOG.archive.md.