Updated the AI testing guide to include the following models with SPLX data: nvidia/NVIDIA-Nemotron-3-Nano-30B-A3B-Base-BF16 and nvidia/NVIDIA-Nemotron-3-Nano-30B-A3B-FP8
Added new behaviors within the following range to the reference docs: BH11937 - BH11956
Removed the quarantine reason from the package header in the Community quick start, as it is no longer displayed in the UI. The rules for quarantining packages remain unchanged
Added Spectra Assure scanning guidelines to help users understand which parts of a software package are scanned based on its package type. The guidelines include a general introduction to scanning with Spectra Assure, as well as guides for specific package types, including ML models and VM images
Added new services to the following service categories:
Chat exchange: SAP Emarsys Messaging API, SAP Emarsys Send Message API, SAP Emarsys SMS Partner API
Data exchange: Mimecast API, SAP Emarsys API, Sophos API
Mail exchange: SAP Emarsys Email Campaign API, SAP Emarsys Send Email API
Updated the rl-protect download links and hashes for version 1.1.0
Updated a list of supported package manifests for the latest version of rl-protect
Updated the rl-protect server list command to display user account details, monthly quota, and current usage information
Added new --target-* options to the rl-protect scan command. Use these options to select a specific artifact of a published software package version for rl-protect to scan. Note that combining different --target-* options comes with some restrictions
Added usage examples for rl-protect commands to illustrate common usage patterns
Updated the descriptions for release_date and is_released fields in the Portal API reference documentation. If a version is released but the release date is omitted, the release_date value defaults to the current date
Added the following secrets to the list of supported secrets: Private Packagist API credentials, Private Packagist Conductor token, Private Packagist organization token, Private Packagist organization read-only token, Private Packagist user token
The Community quick-start guide now includes the Package quarantine section explaining a new flag for open-source software packages that may be unsafe until they can be verified as trustworthy
Updated the AI testing guide to include the following models with SPLX data: deepseek-ai/DeepSeek-V3.2, google/gemma-2-2b-it, google/gemma-2-9b-it, google/gemma-3-270m-it, google/gemma-3n-E2B-it, mistralai/Devstral-Small-2-24B-Instruct-2512, mistralai/Ministral-3-3B-Instruct-2512, mistralai/Ministral-3-8B-Instruct-2512, mistralai/Ministral-3-14B-Instruct-2512
Created an API usage tiers and upgrade guide explaining the differences between Community and Portal APIs and their respective tiers. It also helps users choose the appropriate tier and understand what changes when moving between tiers
Updated the Community API reference documentation with the latest changes released in the API. Note that the repository path parameter has been renamed to community in the "Show report for a package version" and "Show details about a package" endpoints.
Updated the rl-deploy download links and hashes for version 2.6.0
Transformed the list in the Importing files from URLs section of the scan command page into a table to make the information on the supported URLs and PURLs more readable
Renamed the Analysis reports category under Concepts & Reference to Schemas. This category now contains Configuration schemas and Report schemas to highlight the difference between different schemas
Created a new Manage CLI Capacity page where Organization Administrators can allocate portions of the total monthly quota to each registered CLI site key, ensuring that each CLI's dedicated quota is preserved and cannot be consumed by other CLIs within the organization