v3.2 — Release Notes¶
Covers: v3.2.0 – v3.2.40 (2026‑06‑11 to 2026‑08‑17) Audience: All users. Items relevant only to administrators are marked.
This page summarizes the TrustSource v3.2 series, dominated by a major overhaul of Threat Modelling. For the complete, version-by-version list of every change, see the CHANGELOG in the repository.
Added¶
- Threat Modelling gained an AI-driven generation agent: a Generate button starts an automated run that builds the system model, identifies risks and develops countermeasures, with a live progress panel (status, elapsed time, per-phase progress) instead of a plain spinner. You can now choose which stage to run (build model only, generate risks only, develop countermeasures only, or the full pipeline), and re-run any single stage from the model's Lifecycle menu without starting over. See Threat Modelling for the current workflow.
- The threat model is shown as an interactive Data Flow Diagram (pan, zoom, fit, auto-layout, SVG/PNG export, fullscreen, dark mode). Manually arranged node positions are now saved and preserved across reloads and re-runs, and diagrams with many vulnerabilities cap badges at five with a "+N more" expandable list.
- Project Settings can now populate a project's Application goals by
uploading an
architecture.mdfile instead of retyping it; uploads are automatically screened for prompt-injection attempts before use. - New risk origin "Threat Model Assessment (TMA)" for risks created by the threat-model agent, with full threat-model context (STRIDE/ENISA categories, CWEs, trust-boundary crossing) shown wherever the risk is viewed or edited.
- Requesting an approval is now near-instant: the request is created immediately and you're taken to the finalize page, where the Compliance Report, SoUP, Notice and SBOM documents generate in the background with a live per-document progress view.
- New read-only REST endpoints for imported SARIF test results.
Improved¶
- Administrators: accounts that are suspended (by an operator) or automatically flagged as suspicious are now blocked at sign-in and, within seconds, locked out of any already-open session — suspension is managed outside the main application, not from a page inside TrustSource.
- New self-service registrations are now plausibility-checked; a flagged sign-up doesn't receive the verification link and is asked to contact support instead. Genuine sign-ups are unaffected.
- Company API keys and external integration credentials are now encrypted at rest. Nothing changes for you — the masked key view and copy button work exactly as before, and every copy is recorded in the audit log.
- The Administration menu's Integrations entry (GitHub, Jira, TFS, SCANOSS, Webhooks, LeanIX), briefly dropped during a menu restructure, is back.
- Requesting a password reset or an invite/enrollment email now works reliably when an email address is attached to more than one account.
Fixed¶
- Component index search (used when adding a component) no longer collapses differently-versioned packages that share a display name into one result.
- The license pickers on a component's edit page now work on a hard refresh or bookmarked link, not only when navigated to from inside the app.
- The "Change selected license" dialog for multi-license components no longer sometimes opens twice.
Security¶
- Administrators: if your enterprise account uses the company switcher or the enterprise company list, rotate the affected companies' API keys, CSAF feed keys and integration tokens after upgrading — a prior version could expose sibling companies' credentials to enterprise admins browsing that list. See the CHANGELOG (3.2.14) for details.
- Hardened the real-time data connection so it can only be opened from the TrustSource site itself, closing a path where a leaked session token combined with a third-party page could act on a user's behalf.
- Hardened the Jira, TFS and webhook integrations against saving or calling a URL that points at an internal, private or cloud-metadata address.
- User-administration data returned to the app no longer includes password hashes or enrollment/reset/session tokens.
- Messages, status changes and approvals are now strictly scoped to the posting user's own organization; a reference to another organization's project or module is rejected instead of silently applied.
See also: v3.3 — Release Notes · Release Notes index