Skip to content

release 1.0.3 - #264

Merged
Polliog merged 42 commits into
mainfrom
develop
Jun 26, 2026
Merged

release 1.0.3#264
Polliog merged 42 commits into
mainfrom
develop

Conversation

@Polliog

@Polliog Polliog commented Jun 26, 2026

Copy link
Copy Markdown
Collaborator

Release 1.0.3 (2026-06-26). Promotes the current develop line to main. No database migrations; drop-in upgrade.

This is a security-focused release.

Security

Resolves a batch of privately reported issues (coordinated disclosure via KIberblick.de):

Also: trace span attributes are now PII-masked, and service.name is sanitized at ingestion as defense in depth.

Other changes (since 1.0.2)

  • Sigma detection honors full SigmaHQ field-modifier chains; service-map p95 is a true window percentile on every storage engine (issue Bug-hunt follow-ups: Sigma compound modifiers + true service-map p95 #255).
  • Multi-engine reservoir.getSpanTimeseries so trace volume/latency panels work on ClickHouse and MongoDB.
  • Activity Overview on the project overview page; admin usage access fix; en-US locale sweep.
  • Operational fixes: Redis memory leak (BullMQ job retention) and a nightly SigmaHQ sync that re-imported the whole catalog as enabled.

Full detail in CHANGELOG.md under [1.0.3].

After merge: tag v1.0.3 on main.

Polliog and others added 30 commits June 22, 2026 09:30
…-255

fix sigma modifier chains and true multi-engine service-map p95
…icemap-xss

fix cross-tenant dashboard read and service-map stored xss
Comment thread packages/backend/src/tests/modules/dashboard/routes.test.ts Dismissed
@Polliog
Polliog merged commit 8423202 into main Jun 26, 2026
13 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants