Product changes

Release notes

Follow confirmed PurpleWASP product and documentation changes, including new capabilities, resolved issues, administrator actions and links to updated guidance.

Latest GitHub App Integration v1

GitHub security evidence and optional event-driven refresh

GitHub App integration now supports independently enabled organisation, repository, code-security and audit collection, plus optional webhook-triggered refresh of applicable Control evidence.

New and improved
  • Added four GitHub evidence-collection capabilities with explicit partial/unavailable results where provider permissions, API access or plan features limit coverage.
  • Added an opt-in Auto-Refresh switch in the GitHub integration Configuration tab, independent of scheduled collection; it is off by default.
  • Supported GitHub events can now prompt repository/security collection in the background, with verified events retained as delivery history even when Auto-Refresh is disabled.
  • Repository security changes were validated end-to-end through a Control reassessment and integration evidence history: newest evidence current, superseded evidence archived.
  • Updated step-by-step configuration guidance and operational documentation for GitHub App installation and evidence refresh.
Resolved issues
  • Documented the existing restriction that an individual GitHub App installation must not be actively linked to multiple PurpleWASP organisations.
  • Validated the Auto-Refresh disabled state: incoming supported events are stored without scheduling an integration collection.
Google Workspace Integration v1

Google Workspace Identity and Audit integration completed for production

PurpleWASP now supports one OAuth-connected Google Workspace tenant with independently enabled Identity and Audit capabilities, normalized observations and Control evidence automation.

New and improved
  • Added google_workspace.identity for Directory users, groups, role assignments, MFA summary and collection-status observations.
  • Added google_workspace.audit for Admin, Login and OAuth Token audit activity, normalized signals, collection status and independent stream watermarks.
  • Added centrally managed Google OAuth application credentials with encrypted organisation refresh-token storage and environment-aware callback resolution.
  • Added automated evidence for active-user and privileged-user MFA enrollment against adopted CTRL-IAM-03 and audit logging availability against adopted CTRL-LOG-01.
  • Completed production acceptance for OAuth consent/callback, Test Connection, manual worker execution, observations, audit watermarks and evidence provenance.
Resolved issues
  • Documented exact Google OAuth redirect-URI matching for production deployments, including extensionless canonical routing.
  • Confirmed persistent Integration Management workers must be restarted after provider/runtime PHP deployment so new Google dispatchers/classes are loaded.
AWS Integration v1

AWS multi-capability integration and automated Control evidence completed

PurpleWASP now supports one AWS account connection with eight independently enabled inventory, audit and security capabilities. AWS collection feeds Asset and Control consumers through the same collect-once, Control-first architecture used by other providers.

New and improved
  • Added aws.account_inventory, aws.iam_security, aws.resource_inventory, aws.cloudtrail_audit, aws.config_compliance, aws.security_hub, aws.guardduty and aws.inspector beneath one AWS provider/account connection.
  • Added access-key and AssumeRole credential resolution, optional ExternalId support, STS identity/account verification and independent capability readiness reporting.
  • Added AWS resource inventory hand-off to Asset Management and Inspector finding materialisation where AWS resources can be matched to PurpleWASP Assets.
  • Added global AWS Control automation for root MFA, root access-key absence, AWS Config recording, CloudTrail logging and GuardDuty enablement with preserved test/evidence/provenance history.
  • Validated framework-neutral evidence fan-out through PurpleWASP Control mappings rather than collecting separately for ISO 27001, NIST, CIS, SOC 2 or Cyber Essentials.
  • Confirmed new organisations clone the current Integration Management and Control Management templates and reuse global automation rules without tenant-specific rule seeding.
  • Completed acceptance with seven AWS capabilities available in the test account; Security Hub was correctly reported unavailable because the account was not subscribed.
Resolved issues
  • Corrected newly created integration-card behaviour so the returned integration ID is adopted immediately and capability controls can load without requiring a page reload/recreation.
Microsoft Integration v1

Microsoft multi-capability integration completed and deployed

PurpleWASP now operates one shared Microsoft tenant connection with independently enabled Entra ID, Microsoft 365 Security, Intune, Defender for Endpoint and Azure capabilities. Entra, M365 Security and Azure have completed acceptance; Intune and Defender are implemented and await licensed-tenant validation.

New and improved
  • Added microsoft.m365_security, microsoft.intune_devices, microsoft.defender_endpoint and microsoft.azure_resources beneath the existing Microsoft provider/tenant connection.
  • Added independent per-capability enable/disable controls while preserving the Microsoft connection as the master authentication boundary.
  • Updated manual Run Sync and scheduled execution behaviour so disabled capabilities are not queued.
  • Added capability-specific readiness semantics so missing licences, tenant provisioning or Azure RBAC do not invalidate the shared Microsoft connection.
  • Validated Microsoft 365 Security Secure Score/control observations and Azure authentication/read probes.
  • Completed deployment acceptance using the canonical Integration Management worker and scheduler paths.
Resolved issues
  • Resolved stale long-running worker behaviour that could keep an older dispatcher map loaded after capability code changes.
  • Resolved Microsoft runtime credential-helper loading so shared encrypted credentials are available to capability collectors.
  • Prevented disabled Intune/Defender capabilities from being queued alongside enabled Microsoft capabilities.
Integration Management v1

Microsoft Entra ID and Qualys moved to the shared Integration Management runtime

PurpleWASP now operates Microsoft Entra ID v1 and Qualys through a shared Integration Management control plane with encrypted credentials, background jobs, normalized observations and downstream Asset/Control consumers.

New and improved
  • Completed Microsoft Entra ID v1 connection testing, Graph collection and normalized identity observations with required versus optional/licence-dependent evidence semantics.
  • Completed Qualys migration to Integration Management while retaining vulnerability-domain processing in Asset Management.
  • Added canonical Integration Management worker and scheduler operation for background execution.
  • Added automated Control test/evidence materialisation for adopted applicable Controls, including idempotency, evidence lifecycle and preserved provenance/history.
  • Standardised Integration Management operational timestamps on UTC and retained local-time display in the UI.
  • Removed the legacy Asset Management integration control-plane runtime and references after cutover validation.
Resolved issues
  • Resolved legacy runtime-path dependencies between Qualys and Asset Management integration helpers.
  • Resolved mixed UTC/local MySQL runtime timestamps for Integration Management jobs/runs/capability state.
  • Resolved evidence-lifecycle re-preparation failures in the affected MySQL archive operation.
Resources update

Release notes added to PurpleWASP Resources

PurpleWASP Resources now includes a dedicated release-notes area so confirmed product and documentation changes can be recorded in one consistent, user-facing history.

New and improved
  • Added Release Notes as a first-class item in the Resources navigation.
  • Added a dedicated release history page with a consistent format for summaries, improvements, fixes, administrator actions and documentation links.
  • Separated release content from the page template so future releases can be added by updating a single release data file.
  • Added a Release Notes entry point to the main Resources page.
Resolved issues

No resolved issues were recorded for this release.

Verified changes only

Release notes are a production record. Planned or unverified work should not be published here.