Skip to content

v3.2 — Release Notes

Covers: v3.2.0 – v3.2.40 (2026‑06‑11 to 2026‑08‑17) Audience: All users. Items relevant only to administrators are marked.

This page summarizes the TrustSource v3.2 series, dominated by a major overhaul of Threat Modelling. For the complete, version-by-version list of every change, see the CHANGELOG in the repository.

Added

  • Threat Modelling gained an AI-driven generation agent: a Generate button starts an automated run that builds the system model, identifies risks and develops countermeasures, with a live progress panel (status, elapsed time, per-phase progress) instead of a plain spinner. You can now choose which stage to run (build model only, generate risks only, develop countermeasures only, or the full pipeline), and re-run any single stage from the model's Lifecycle menu without starting over. See Threat Modelling for the current workflow.
  • The threat model is shown as an interactive Data Flow Diagram (pan, zoom, fit, auto-layout, SVG/PNG export, fullscreen, dark mode). Manually arranged node positions are now saved and preserved across reloads and re-runs, and diagrams with many vulnerabilities cap badges at five with a "+N more" expandable list.
  • Project Settings can now populate a project's Application goals by uploading an architecture.md file instead of retyping it; uploads are automatically screened for prompt-injection attempts before use.
  • New risk origin "Threat Model Assessment (TMA)" for risks created by the threat-model agent, with full threat-model context (STRIDE/ENISA categories, CWEs, trust-boundary crossing) shown wherever the risk is viewed or edited.
  • Requesting an approval is now near-instant: the request is created immediately and you're taken to the finalize page, where the Compliance Report, SoUP, Notice and SBOM documents generate in the background with a live per-document progress view.
  • New read-only REST endpoints for imported SARIF test results.

Improved

  • Administrators: accounts that are suspended (by an operator) or automatically flagged as suspicious are now blocked at sign-in and, within seconds, locked out of any already-open session — suspension is managed outside the main application, not from a page inside TrustSource.
  • New self-service registrations are now plausibility-checked; a flagged sign-up doesn't receive the verification link and is asked to contact support instead. Genuine sign-ups are unaffected.
  • Company API keys and external integration credentials are now encrypted at rest. Nothing changes for you — the masked key view and copy button work exactly as before, and every copy is recorded in the audit log.
  • The Administration menu's Integrations entry (GitHub, Jira, TFS, SCANOSS, Webhooks, LeanIX), briefly dropped during a menu restructure, is back.
  • Requesting a password reset or an invite/enrollment email now works reliably when an email address is attached to more than one account.

Fixed

  • Component index search (used when adding a component) no longer collapses differently-versioned packages that share a display name into one result.
  • The license pickers on a component's edit page now work on a hard refresh or bookmarked link, not only when navigated to from inside the app.
  • The "Change selected license" dialog for multi-license components no longer sometimes opens twice.

Security

  • Administrators: if your enterprise account uses the company switcher or the enterprise company list, rotate the affected companies' API keys, CSAF feed keys and integration tokens after upgrading — a prior version could expose sibling companies' credentials to enterprise admins browsing that list. See the CHANGELOG (3.2.14) for details.
  • Hardened the real-time data connection so it can only be opened from the TrustSource site itself, closing a path where a leaked session token combined with a third-party page could act on a user's behalf.
  • Hardened the Jira, TFS and webhook integrations against saving or calling a URL that points at an internal, private or cloud-metadata address.
  • User-administration data returned to the app no longer includes password hashes or enrollment/reset/session tokens.
  • Messages, status changes and approvals are now strictly scoped to the posting user's own organization; a reference to another organization's project or module is rejected instead of silently applied.

See also: v3.3 — Release Notes · Release Notes index