Changelog

What we've been shipping.

We update nulltribe. roughly every two weeks. Bigger releases get full notes; small tweaks land quietly. Open the main site to try anything new.

2026.06·June 19, 2026

PDF assessment reports + DAST engine choice

  • FeatureFormal PDF assessment reports — full 9-section vulnerability report, downloadable from every scan.
  • FeatureDAST tool toggle — pick between super-fast template scan or deeper behavioural scan.
  • FeatureExcel + CSV finding exports per scan with severity, file, and remediation columns.
  • FixDefault-branch detection — scans now work on any target branch (master / develop / etc.), not just main.
2026.05·May 21, 2026

New engines: Secrets, IaC, Container, Dependencies

  • FeatureSecrets engine — git-history credential leak detection.
  • FeatureIaC-only engine — fast misconfiguration scan for Terraform / Dockerfile / Kubernetes manifests.
  • FeatureContainer engine — pulls any public image (ghcr.io, docker.io, …) and scans for CVEs.
  • FeatureDependencies scan now includes CycloneDX SBOM download.
  • FeatureLicense compliance findings included in dependency scans.
2026.04·April 12, 2026

Triage workflow + finding diff

  • FeatureShareable finding detail pages with a unique URL per finding.
  • FeatureRepo-scoped filter on the vulnerability center — narrow to one target across all scans.
  • Feature"NEW" badges on findings introduced since the previous scan of the same target.
  • Feature"New only" toggle to hide carried-over findings.
2026.03·March 8, 2026

Security hardening

  • SecurityHMAC signature verification on every scan-result ingest — only authorized workers can write findings.
  • SecurityPer-user rate limiting on scan trigger to prevent abuse.
  • SecurityAdmin audit log — every security-relevant action recorded with IP + user agent.
  • Security"Sign out everywhere" button revokes all active sessions across all devices.
2026.02·February 14, 2026

Compliance export + CI severity gate

  • FeatureOne-click compliance ZIP export — scans + findings + summary, ready for SOC 2 / ISO 27001 reviews.
  • FeatureCI severity gate — fail your build pipeline on Critical/High findings via a polling endpoint.
  • FeatureCustom SAST rules — upload your own YAML rule file, runs alongside the default ruleset.
2026.01·January 9, 2026

Platform polish + performance

  • PerfPaginated /vulns and /audit (25–50 per page) — much faster load on large accounts.
  • PerfNew DB indexes on user_id / created_at / severity / job_id — dashboard loads now <100 ms.
  • PerfRealtime notification updates — status changes appear instantly instead of polling every 15 s.
  • FeatureVulnerability center now groups findings by scan with click-to-expand accordion.

Want a feature? Got a bug?

hello@nulltribe.com