Skip to main content

Spectra Assure Docs Changelog

Subscribe to the changelog feed: RSS | Atom | JSON

10 posts tagged with "2025"

View All Tags

ReversingLabs

Documentation release for the Spectra Assure CLI 2.7.0 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.5.1 Portal version.

CLIโ€‹

  • Updated the policy configuration schema

    • provider is a new required field, and flow is required in the networking.protocol.filter.address.service object
    • product, version, publisher and license are now optional in the processing.filter.identity.component and processing.filter.identity.dependency objects
    • description is a new optional field in processing.filter.identity.component and processing.filter.identity.dependency objects
    • editing is a new optional field in the processing.filter.identity.dependency object
    • processing.filter.hunting.behaviors now supports setting a behavior ID to 'pass'
    • a new section processing.filter.hunting.indicators allows targeting behaviors by their description text
  • Updated the policy configuration guides for behaviors and BOM editing according to policy configuration schema changes

  • Reorganized content on the vault command page to make it clearer which options are supported by which sub-command

  • Updated the content on the find command page

    • Added the Dropbox short-lived online and offline access tokens to the Web service access tokens section of supported secrets
    • Noted that behaviors can be searched by ID in the introduction
    • Reorganized specialized CLI options for search terms into their own sections
    • Merged the "Search for specific secrets with evidence" example into the "Find active and exposed secrets in a project" example to simplify the page
    • Changed example headings for clarity

Portalโ€‹

SAFEโ€‹

  • Documented the new "Component Age" section on the Summary page of the SAFE report
  • Updated SAFE Viewer download links and hashes for version 1.3.0
  • Improved the content on the SAFE Viewer page to make the information about the current version more visible and explain the transparency report
  • Reorganized the content on the SAFE report page to reduce duplicated information; added missing references about PDF summary, and indicated where xBOM information can be found in the report

Otherโ€‹

  • Updated product release notes

  • Reorganized content on the Community and language coverage page

    • Virtual Machines are now a standalone section instead of being grouped together with Containers
    • Moved content from tables into simple lists to make it easier to search and navigate
  • Updated the rl-json report schema

    • Added new fields in report.metadata.components.identity, report.metadata.cryptography, report.metadata.dependencies.identity, report.metadata.ml_models, report.metadata.services
    • Updated the catalogue version in the schema
  • Split the report examples from schemas on all report schema pages in conceptual docs for a more consistent structure and easier access to examples

  • Increased font size in all tables to improve readability

ReversingLabs

First release of the Spectra Assure Community documentation.

Communityโ€‹

The Spectra Assure Community product now has a dedicated section on the Spectra Assure docs website.

Previously, the Community item in the top navbar was a direct link to the official Community page. Now it's a dropdown that lets you access new content and makes space for future documentation about the product.

Specifically, the Community section of the docs website now contains:

  • The product landing page that helps you understand how Spectra Assure Community works and what it's best used for
  • The quick start guide that explains the basics of the Spectra Assure Community report and how to share it with others

Otherโ€‹

  • Fixed a broken link to the vault command page in the CLI section of the 2024-04-10 docs changelog entry

ReversingLabs

Documentation release for the Spectra Assure CLI 2.6.3 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.4.2 Portal version.

CLIโ€‹

  • Replaced SAFE with rl-html in the Supported report formats table on the report command page

  • Added explanations for custom return codes communicating the license state to the scan and license commands

Portalโ€‹

  • Updated the SAFE Viewer version, hashes, and download links to v1.2.0

  • Added a section on the auto-approval feature to the Portal Settings page

  • Added the auto-approval feature to the File Stream vs Projects comparison table to indicate that it's supported in both

Otherโ€‹

  • Added an RSS feed to the Changelog page, allowing users to subscribe to docs-related updates via RSS

  • Added new behaviors to the reference docs: BH13778, BH13779, BH13780, BH13781, BH13782, BH13783, BH13784, BH13785, BH13786, BH13787, BH13788, BH13789, BH13790, BH13791, BH13792, BH13793, BH13794, BH13795, BH13796, BH13797, BH13798, BH13799, BH13800, BH13801, BH13802, BH13803, BH13804, BH13805, BH13806, BH13807, BH13808, BH13809, BH13810, BH13811, BH13812, BH13813, BH13814, BH13815, BH13816, BH13817, BH13818, BH13819, BH13820, BH13821, BH13822, BH13823, BH13824, BH13825, BH13826, BH13827, BH13828, BH13829, BH15343, BH15344, BH15345, BH15346, BH15347, BH15348, BH15349, BH15350, BH15351, BH15352, BH15353, BH15354, BH15355, BH16389, BH16390, BH19570

  • Updated the product release notes

  • Mentioned the new Malware page of the report where applicable and updated the graphics to illustrate the changes

  • Added Coinminer, Dropper, and Mail to the list of supported threat types

  • Declared the SQ30101 policy as enabled by default

  • Removed the incorrect statement on ML models from the ML-BOM section of the xBOM page

  • Updated the link to the ReversingLabs EULA in the API reference documentation

  • Fixed a broken anchor link on the CLI report command page

  • Corrected the wrong rl-deploy version number in the last docs changelog update

ReversingLabs

Documentation release for the Spectra Assure CLI 2.6.2 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.4.1 Portal version.

CLIโ€‹

  • Added a new status sub-command to rl-secure vault that checks if the password vault has been initialized for the specified package store

  • Added Palantir JWT to the list of supported secrets under the find command

  • Updated the rl-deploy version, release date, links, and hashes to v2.3.1

Otherโ€‹

  • Added new behaviors to the reference docs: BH13765, BH13766, BH13767, BH13768, BH13769, BH13770, BH13771, BH13772, BH13773, BH13774, BH13775, BH13776, BH13777

  • Removed the incorrect reference to rl-cve from the rl-uri report schema frontmatter

  • Fixed a broken link in the Suppress secrets policy configuration guide

  • Fixed tags in the report example on the rl-uri report schema page

  • Removed the duplicate listing of differential analysis policies on the Policies > Threat hunting page

  • Transformed SAFE and Integrations categories into dropdowns. All important pages in these categories can now always be accessed from any part of the docs

  • Fixed the CBOM glossary entry to mention that it's included only in the CycloneDX report format

ReversingLabs

Documentation release for the Spectra Assure CLI 2.6.1 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.3.2 Portal version.

CLIโ€‹

  • Added Anthropic API key to the list of supported secrets under the find command

  • Updated the main policy configuration example with new sections

  • Updated phrasing in all policy configuration guides to clarify where and how policy changes apply, and which policy configuration objects are used

  • Created a policy configuration guide for declaring network services

  • Created a policy configuration guide for BOM editing

  • Updated the instructions for networking filters to match the new opt-in behavior for declaring networking placeholders

  • Updated the policy configuration schema with new objects supported in the xBOM release (networking.protocol.filter.address.service, processing.filter.identity.component, processing.filter.identity.model_card, processing.filter.identity.dependency)

  • Updated the rl-checks report schema with objects added in the xBOM release (report.scans.scan-{type}.rl_store, report.scans.scan-{type}.assessments.assessment.evaluations)

Portalโ€‹

  • Updated the Portal API specification:

  • Updated SAFE Viewer version, hashes, and download links to v1.1.1

Otherโ€‹

ReversingLabs

Documentation changes related to the Spectra Assure CLI 2.6.0 / 2025.3.1 Portal product update.

Integrationsโ€‹

Otherโ€‹

ReversingLabs

Documentation release for the Spectra Assure CLI 2.6.0 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.3.1 Portal version.

CLIโ€‹

  • Added new --[show-]models, --[show-]sbom, --[with-]license, and --no-dep[endencie]s options to the inspect command. Their usage has been illustrated by accompanying examples

  • Added the --no-tracking option to the report command

  • Marked the --no-vex option as deprecated in the report command

  • Expanded the admonition about --keep-reference on the rl-secure scan command page to include the Windows issue

  • Added the Windows issue regarding symbolic links to the CLI Troubleshooting page

SAFEโ€‹

  • Updated the SAFE Viewer version, release date, links, and hashes to v1.1.0

Otherโ€‹

  • Created a new How Spectra Assure analyzes software page under Concepts & Reference that explains the different stages in the analysis process. A diagram was used to visualize the entire process and make the order of analysis steps easier to understand

  • Created a new Services category under Concepts & Reference, containing all supported SaaSBOM services sorted by type

  • Reorganized the tables on the Community and language coverage page to improve search, navigation, and content maintenance

  • Added the following new policies to the documentation:

    • New policies in the Malware detection category focus on adware, PUAs and low-quality content in software components and their dependencies: SQ30121, SQ30205, SQ30122, SQ30204, SQ30201, SQ30206, SQ30203, SQ30202

    • New policies in the Digital signatures category focus on issues with countersigning and integrity validation of signatures: SQ20133, SQ20136, SQ20135, SQ20134, SQ20132

    • New policies in the Threat hunting category focus on developer reputation, detecting additional known software supply chain compromises, and identifying behaviors typical for infostealer, keylogger, and rootkit malware: TH15110, TH15403, TH20108, TH20113, TH15402, TH15401, TH20114, TH20112, TH18201, TH15405, TH15108, TH18202, TH15109, TH20110, TH15404, TH20109, TH20111

  • Updated the verified glossary entry with new verification types

  • Added new glossary entries for SaaSBOM, CBOM, ML-BOM, BOV, and VEX

  • Updated the Spectra Assure analysis reports page with new information on new Bill of Materials formats

  • Updated the product release notes

  • Added BTRFS filesystem support on Community and language coverage and File format coverage pages

  • Updated the CycloneDX and SPDX versions in the docs. We're now using CycloneDX 1.6 and SPDX 3.0.1

ReversingLabs

Documentation release for the Spectra Assure CLI 2.5.5 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.2.2 Portal version.

CLIโ€‹

  • Updated the rl-deploy version, release date, links, and hashes to v2.3.0

Portalโ€‹

  • Made a new Best practices for working with projects guide in the Portal docs. It includes the best naming practices, as well as all important information on the projects hierarchy and usage on Spectra Assure Portal

  • Separated the workflows from the Portal File Stream and Projects pages. This helps users focus on the actions available on each page, without having to scroll through the general information every time

  • Simplified the File Stream and Projects workflows and added roles tags to each. This eliminates the need to check the User and group management page for every action

  • Replaced all screenshots with interactive guides in the Portal docs

SAFEโ€‹

  • Moved the Reproducibility check section from the Projects page to the Report landing page

  • Updated the SAFE Viewer version, release date, links, and hashes to v1.0.4

  • Added information on the new File Stream header to the Summary page of the SAFE report. It allows users to export parts of the report in various formats and move the version to a project of their choice right from the top of the landing page of the report

  • Removed the incorrectly included RAT from the list of Threat types on the Summary page of the report

Otherโ€‹

  • Re-designed API, Portal, and CLI category landing pages to look the same as Integrations, Partners, and SAFE category landing pages in our docs

  • Moved Reproducibility checks, Live secret validation, and Managing third-party risks guides to a new Conceptual guides sidebar category

ReversingLabs

Documentation release for the Spectra Assure CLI 2.5.4 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.2.1 Portal version.

CLIโ€‹

  • Updated the rl-deploy version, release date, links, and hashes to v2.2.9

  • Updated the rl-secure list and rl-secure report pages to indicate that those commands don't require an active license

Portalโ€‹

  • Added the new Entitlements section to the Settings page. It allows users to check which SAFE Assessment categories are enabled for their ReversingLabs cloud account and are evaluated during software analysis

  • Made changes to the Settings page. Screenshots on the page have been replaced with interactive guides, while the textual content has been refreshed

  • Fixed the incorrect year in the 2025.1.2 version title in the Portal release notes

Integrationsโ€‹

  • Information about the ServiceNow integration can now be accessed from the Integrations page

  • Added support for creating the PDF summary (rl-summary-pdf) to the Portal Docker image documentation

SAFEโ€‹

  • Updated the information relating to the SAFE Assessment part of the report summary

  • Updated the SAFE Viewer version, release date, links, and hashes to v1.0.3

Otherโ€‹

ReversingLabs

Documentation release for the Spectra Assure CLI 2.5.3 product update.

New release of the Spectra Assure Portal and Public API documentation, covering the 2025.1.2 Portal version.

The docs homepage has a new look!

For a fresh start to the new year, we've slightly redesigned the home page.

There's a new product card for Integrations, a new section with a link to this changelog, and improved descriptions for Featured content.

CLIโ€‹

  • Updated the information on Entitlements. Entitlements are now more dynamic, since they're no longer tied to the user license, but to the user account

  • Updated the list of secrets supported by the find command

Portalโ€‹

  • Added the new PDF Summary export feature to the Portal and API docs

  • Resolved minor issues in the Portal API reference docs:

    • Fixed the incorrect response message when trying to replace a version
    • Fixed the incorrect request body in Approval (TPRM) endpoints that misrepresented the reason field as optional
    • Removed 400 responses from endpoints that don't support them; replaced generic 404 response for reports with more specific messages
    • Changed content types in response schemas to match the file format that the API returns and clarified response handling for report content
    • Updated request code examples with placeholder value for report type

Integrationsโ€‹

  • Linked the new JFrog Artifactory integration in CLI and Portal sections

SAFEโ€‹

  • Updated the SAFE Viewer version, download links, and hashes. The "Current version" admonition now also shows the release date of the latest version

Otherโ€‹

  • Updated the product release notes

  • Added a short description of the new PDF Summary export to the Analysis reports page

  • Removed all references to the unused endpoint (api.reversinglabs.com) from the docs