v3.3 — Release Notes¶
Covers: v3.3.0 – v3.3.22 (2026‑07‑17 to 2026‑08‑13) Audience: All users. Items relevant only to administrators are marked.
This page summarizes the TrustSource v3.3 series. For the complete, version-by-version list of every change, see the CHANGELOG in the repository.
Added¶
- CVD cases — a new Outbound → CVD cases area for companies with Coordinated Vulnerability Disclosure enabled: a list and detail view for the cases held in the connected CVD platform, with case creation directly from TrustSource. See CVD cases for the full workflow, including how to open a case from the Vulnerability report or from a CSAF document.
- A CVSS-vs-EPSS risk-overview chart on the Vulnerability report, plotting every finding by severity score and real-world exploitation probability — in both the on-screen report and the exported PDF.
- An advisory (CSAF/VEX) can now record the CVD case it belongs to, so a reader can trace a published advisory back to the disclosure that produced it.
- New read-only REST endpoints expose CVSS environmental context and SARIF test-result data for external security tooling.
Improved¶
- Creating, importing or exporting a CSAF document, and opening a CVD case, now consistently require compliance manager, manager, security manager or account-administrator rights — enforced the same way everywhere, not only in the interface. Administrators: this may remove access some accounts had in practice before; check who in your company uses these pages.
- Company security managers can now see and open CVD cases, the same as compliance managers and administrators already could.
- The API-keys copy button now reliably copies the key — or clearly says why it could not — instead of silently placing "undefined" on the clipboard.
- SBOM CycloneDX export gained a dedicated AI/ML (AIBOM) option, and the combined export is now labelled "Full BOM (components + crypto + AI)".
- SBOM import is more robust: container/distro images with circular dependency graphs (e.g. Debian's libc6 ↔ libgcc-s1) and very deep dependency chains now import completely instead of failing.
- A scan uploaded through the v1 scan API is no longer stored without its dependency tree.
- Billing details saved on Account & Billing now take effect immediately, without a page reload.
- The Identity Integration pages now state plainly when no identity provider is configured, instead of failing in several confusing ways.
Fixed¶
- The CVE impact report now describes GitHub Security Advisories (GHSA identifiers) with their full severity and description, instead of showing an empty entry.
- A license whose text TrustSource doesn't hold now says so and links to the official text, instead of showing an empty panel.
- Several stability fixes to dependency lists, compliance reports and approval requests in self-hosted/local setups.
- The public SBOM and Notice endpoints now answer failures with the correct HTTP status instead of always reporting "200 OK", so integrations can tell a missing document from a successful one.
Security¶
- Notification pop-ups now always show their text as plain text, closing a path where a relayed message could have run script content in the browser.
- Advisory identifiers published in a CSAF/VEX document can no longer be reversed to recover internal module identifiers, and can no longer be forged — the key used to obscure them now stays server-side only.
- Outbound integration requests (CVD, Jira, TFS, webhooks) no longer follow a redirect to a different host while still carrying the original credentials or request content.
- Company data shown when creating a CSAF document or a CVD case is now established from the signed-in session on the server, not from what the browser claims.
See also: v3.2 — Release Notes · Release Notes index