Skip to content

v3.3 — Release Notes

Covers: v3.3.0 – v3.3.22 (2026‑07‑17 to 2026‑08‑13) Audience: All users. Items relevant only to administrators are marked.

This page summarizes the TrustSource v3.3 series. For the complete, version-by-version list of every change, see the CHANGELOG in the repository.

Added

  • CVD cases — a new Outbound → CVD cases area for companies with Coordinated Vulnerability Disclosure enabled: a list and detail view for the cases held in the connected CVD platform, with case creation directly from TrustSource. See CVD cases for the full workflow, including how to open a case from the Vulnerability report or from a CSAF document.
  • A CVSS-vs-EPSS risk-overview chart on the Vulnerability report, plotting every finding by severity score and real-world exploitation probability — in both the on-screen report and the exported PDF.
  • An advisory (CSAF/VEX) can now record the CVD case it belongs to, so a reader can trace a published advisory back to the disclosure that produced it.
  • New read-only REST endpoints expose CVSS environmental context and SARIF test-result data for external security tooling.

Improved

  • Creating, importing or exporting a CSAF document, and opening a CVD case, now consistently require compliance manager, manager, security manager or account-administrator rights — enforced the same way everywhere, not only in the interface. Administrators: this may remove access some accounts had in practice before; check who in your company uses these pages.
  • Company security managers can now see and open CVD cases, the same as compliance managers and administrators already could.
  • The API-keys copy button now reliably copies the key — or clearly says why it could not — instead of silently placing "undefined" on the clipboard.
  • SBOM CycloneDX export gained a dedicated AI/ML (AIBOM) option, and the combined export is now labelled "Full BOM (components + crypto + AI)".
  • SBOM import is more robust: container/distro images with circular dependency graphs (e.g. Debian's libc6 ↔ libgcc-s1) and very deep dependency chains now import completely instead of failing.
  • A scan uploaded through the v1 scan API is no longer stored without its dependency tree.
  • Billing details saved on Account & Billing now take effect immediately, without a page reload.
  • The Identity Integration pages now state plainly when no identity provider is configured, instead of failing in several confusing ways.

Fixed

  • The CVE impact report now describes GitHub Security Advisories (GHSA identifiers) with their full severity and description, instead of showing an empty entry.
  • A license whose text TrustSource doesn't hold now says so and links to the official text, instead of showing an empty panel.
  • Several stability fixes to dependency lists, compliance reports and approval requests in self-hosted/local setups.
  • The public SBOM and Notice endpoints now answer failures with the correct HTTP status instead of always reporting "200 OK", so integrations can tell a missing document from a successful one.

Security

  • Notification pop-ups now always show their text as plain text, closing a path where a relayed message could have run script content in the browser.
  • Advisory identifiers published in a CSAF/VEX document can no longer be reversed to recover internal module identifiers, and can no longer be forged — the key used to obscure them now stays server-side only.
  • Outbound integration requests (CVD, Jira, TFS, webhooks) no longer follow a redirect to a different host while still carrying the original credentials or request content.
  • Company data shown when creating a CSAF document or a CVD case is now established from the signed-in session on the server, not from what the browser claims.

See also: v3.2 — Release Notes · Release Notes index