<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>LimaCharlie Release Notes: Platform</title>
    <link>https://docs.limacharlie.io/10-release-notes/</link>
    <description>Platform announcements that are not tied to one component.</description>
    <language>en</language>
    <generator>LimaCharlie Documentation release feed hook</generator>
    <lastBuildDate>Thu, 20 Aug 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://docs.limacharlie.io/10-release-notes/platform.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Platform: Multi-Provider AI Sessions</title>
      <link>https://docs.limacharlie.io/10-release-notes/#platform-multi-provider-ai-sessions</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-08-20:release/platform-multi-provider-ai-sessions</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;h4 id="new-features_2"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI provider choice for user sessions&lt;/strong&gt;: user AI Sessions can now run on OpenAI (API key or Azure OpenAI), Google Gemini (AI Studio key or Vertex AI service account), and OpenRouter, in addition to Claude. Connect your own provider credentials under &lt;strong&gt;User Settings → AI Terminal&lt;/strong&gt; (or via the API) and pick the provider on a session profile. Tool use and approvals, MCP servers, USD budget caps, hibernation, forking, and cost tracking work the same on every provider; a few capabilities stay Claude-only (plan mode, &lt;code&gt;bypassPermissions&lt;/code&gt;, Task subagents, extended thinking). See &lt;a href="https://docs.limacharlie.io/9-ai-sessions/providers/"&gt;AI Providers&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Vulnerability Management Uplift</title>
      <link>https://docs.limacharlie.io/10-release-notes/#vulnerability-management-uplift</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-05-09:release/vulnerability-management-uplift</guid>
      <pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;p&gt;Major uplift to the Vulnerability Reporting extension and its surfaces.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Canonical asset-tag namespace&lt;/strong&gt;: introduces the &lt;code&gt;lc:asset:*&lt;/code&gt; tag convention (criticality, exposure, environment, owner, compliance) for cross-cutting asset metadata. The Vulnerability Reporting extension is the first consumer; the namespace is intended to be reused across LimaCharlie surfaces. See &lt;a href="https://docs.limacharlie.io/2-sensors-deployment/asset-tags/"&gt;Asset &lt;abbr title="Tags in LimaCharlie are strings linked to sensors for classifying endpoints, automating detection and response, and triggering workflows. Tags appear in every event under the `routing` component and help simplify rule writing. Tags can be added manually, via API, or through detection &amp;amp; response..."&gt;Tag&lt;/abbr&gt; Namespace&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability Reporting extension&lt;/strong&gt;: new public-facing documentation covering setup, scan modes (&lt;code&gt;scheduled&lt;/code&gt; / &lt;code&gt;manual&lt;/code&gt; / &lt;code&gt;all&lt;/code&gt;), criticality-tag overrides, KEV + EPSS enrichment, LC Risk scoring, and the full action surface. See &lt;a href="https://docs.limacharlie.io/5-integrations/extensions/limacharlie/vulnerability-reporting/"&gt;Vulnerability Reporting&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Finding resolutions&lt;/strong&gt;: documented the resolution model — every finding is implicitly &lt;strong&gt;open&lt;/strong&gt; until an operator records &lt;code&gt;mitigated&lt;/code&gt;, &lt;code&gt;accepted&lt;/code&gt;, or &lt;code&gt;false_positive&lt;/code&gt;. Accepted-exception expiries lapse back into the open count, and &lt;code&gt;vuln_finding.*&lt;/code&gt; events (&lt;code&gt;created&lt;/code&gt;, &lt;code&gt;closed&lt;/code&gt;, &lt;code&gt;kev_match&lt;/code&gt;, &lt;code&gt;state_changed&lt;/code&gt;) can be routed via Outputs to Jira, Slack, Cases, etc.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Other Notable Updates</title>
      <link>https://docs.limacharlie.io/10-release-notes/#other-notable-updates</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-08-28:release/other-notable-updates</guid>
      <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Org Templates&lt;/strong&gt;: Re-introduction of org templates during org creation. Currently offering &lt;abbr title="Endpoint Detection &amp;amp; Response"&gt;EDR&lt;/abbr&gt; Quick Start and Basic Browser Monitoring to get the new org configured on creation. You can always add configurations as code using the &lt;abbr title="Infrastructure as Code (IaC) automates the management and provisioning of IT infrastructure using code, making it easier to scale, maintain, and deploy resources consistently. In LimaCharlie, IaC allows security teams to deploy and manage sensors, rules, and other security infrastructure..."&gt;IaC&lt;/abbr&gt; Generator.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Parsing Unstructured Logs&lt;/strong&gt;: With &lt;code&gt;parsing_grok&lt;/code&gt; you can use OpenSearch Grok processor syntax, and tap into powerful ready-to-use Grok patterns and the vast knowledge of grokking data with Elastic.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>New Community Rule Sets</title>
      <link>https://docs.limacharlie.io/10-release-notes/#new-community-rule-sets</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-06-27:release/new-community-rule-sets</guid>
      <pubDate>Fri, 27 Jun 2025 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;p&gt;Two new rule sets from community partners added to the LimaCharlie Add-Ons collection:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SoteriaSec Commercial Ruleset&lt;/strong&gt;: Google Workspace Rules&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;BLOKWORX Detection &amp;amp; Response&lt;/strong&gt;: Rules covering detection of a collection of remote access services usage&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>LimaCharlie Endpoint Protection</title>
      <link>https://docs.limacharlie.io/10-release-notes/#limacharlie-endpoint-protection</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-05-20:release/limacharlie-endpoint-protection</guid>
      <pubDate>Tue, 20 May 2025 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;p&gt;Releasing LimaCharlie Endpoint Protection, which integrates with third-party &lt;abbr title="Endpoint Detection &amp;amp; Response"&gt;EDR&lt;/abbr&gt; solutions to provide a better view of security operations and extend agent capabilities. This functionality comprises the EPP &lt;abbr title="LimaCharlie Extensions allow users to expand and customize their security environments by integrating third-party tools, automating workflows, and adding new capabilities. Organizations subscribe to Extensions, which are granted specific permissions to interact with their infrastructure. Extensions..."&gt;Extension&lt;/abbr&gt;, Web App, and a previously released &lt;abbr title="Endpoint Agents are lightweight software agents deployed directly on endpoints like workstations and servers. These sensors collect real-time data related to system activity, network traffic, file changes, process behavior, and much more."&gt;Endpoint Agent&lt;/abbr&gt; v4.33.6.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LimaCharlie Labs</title>
      <link>https://docs.limacharlie.io/10-release-notes/#limacharlie-labs</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-02-28:release/limacharlie-labs</guid>
      <pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;p&gt;Introducing LimaCharlie Labs, where we share brave experiments and early prototypes of features and extensions that may or may not become production, based on your input and feedback. Check the LABS badge on the Web App.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Playbook &lt;abbr title="LimaCharlie Extensions allow users to expand and customize their security environments by integrating third-party tools, automating workflows, and adding new capabilities. Organizations subscribe to Extensions, which are granted specific permissions to interact with their infrastructure. Extensions..."&gt;Extension&lt;/abbr&gt;&lt;/strong&gt; is now available in Labs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New MITRE Report API</title>
      <link>https://docs.limacharlie.io/10-release-notes/#new-mitre-report-api</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2024-10-28:release/new-mitre-report-api</guid>
      <pubDate>Mon, 28 Oct 2024 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;p&gt;Added a new REST API and &lt;abbr title="Command-line Interface"&gt;CLI&lt;/abbr&gt; for producing a MITRE report for a given organization based on the &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt; rules in place (using their tags like &lt;code&gt;attack..t1000.xxx&lt;/code&gt;).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Command-line Interface"&gt;CLI&lt;/abbr&gt;&lt;/strong&gt;: &lt;code&gt;limacharlie mitre-report&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The resulting JSON report can be used with the &lt;a href="https://mitre-attack.github.io/attack-navigator/"&gt;ATT&amp;amp;CK Navigator&lt;/a&gt;. This capability makes it easier to track security coverage against the MITRE ATT&amp;amp;CK framework.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Sort and Bulk Actions for Tables</title>
      <link>https://docs.limacharlie.io/10-release-notes/#new-sort-and-bulk-actions-for-tables</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2024-10-17:release/new-sort-and-bulk-actions-for-tables</guid>
      <pubDate>Thu, 17 Oct 2024 00:00:00 GMT</pubDate>
      <category>platform</category>
      <description>&lt;p&gt;Added the ability to sort columns in the LimaCharlie web app. In addition, tables now support bulk actions (Enable/Disable and Delete). This applies to the following sections: Adapters, YARA Rules, Secrets, Lookups, False Positive Rules, and Detection and Response Rules.&lt;/p&gt;
&lt;!-- Glossary definitions for tooltip abbreviations --&gt;
&lt;!-- Auto-generated from glossary CSV - do not edit manually --&gt;</description>
    </item>
  </channel>
</rss>
