<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>LimaCharlie Release Notes: Web App</title>
    <link>https://docs.limacharlie.io/10-release-notes/</link>
    <description>Releases of the LimaCharlie web application.</description>
    <language>en</language>
    <generator>LimaCharlie Documentation release feed hook</generator>
    <lastBuildDate>Thu, 20 Aug 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://docs.limacharlie.io/10-release-notes/web-app.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Web App 6.2.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-620</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-08-20:release/web-app-6-2-0</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Resizable columns on every table, more of LimaCharlie extensions moving onto first-class pages, multi-provider credentials for AI Sessions, better reporting when a search leaves events out, and keyboard navigation in the org pickers.&lt;/p&gt;
&lt;h4 id="new-features_1"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Resizable columns on every table&lt;/strong&gt;: column resizing is now on by default for every table in the app, not just Search results.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Query Console tells you when a search left events out&lt;/strong&gt;: a search that sheds events used to report "Complete!" regardless, and a query whose only match was skipped rendered as "no results". A warning badge in the status row now carries the headline count ("16 events skipped"), and a notice card above the results — closed by default — carries the per-reason breakdown, an explanation of why the search moved past those events rather than stalling, and a sampled list of them.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dedicated YARA Scanners page&lt;/strong&gt;: &lt;code&gt;ext-yara&lt;/code&gt; replaces the generic schema-driven renderer with a first-class page at &lt;code&gt;/orgs/:oid/yara-scanners&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dedicated File &amp;amp; Registry Integrity page&lt;/strong&gt;: &lt;code&gt;ext-integrity&lt;/code&gt; replaces the generic schema-driven renderer with a first-class page at &lt;code&gt;/orgs/:oid/integrity&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dedicated &lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Cull page&lt;/strong&gt;: &lt;code&gt;ext-sensor-cull&lt;/code&gt; replaces the generic schema-driven renderer with a first-class page at &lt;code&gt;/orgs/:oid/sensor-cull&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI Sessions: multi-provider credentials&lt;/strong&gt;: alongside Anthropic, you can now connect OpenAI, Google Gemini and OpenRouter, each with its own auth methods (API key, Azure OpenAI, Vertex for Gemini, Bedrock/Vertex for Anthropic). Session profiles gain a Provider select, session details show which provider a session ran on. See User Settings → AI Terminal.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Keyboard navigation in the org pickers&lt;/strong&gt;: both the full-screen &lt;code&gt;/orgs&lt;/code&gt; list and the bottom-left org switcher autofocus their search field, let Tab move into the results, arrow keys move the highlight and Enter selects. A single filtered match is preselected, so typing enough to narrow to one org and pressing Enter enters it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Export affected hosts from Vulnerability Reporting&lt;/strong&gt;: an Export hosts control (CSV or Excel) on the CVE detail page, the CVE drawer's Impacted Assets tab, and the package drawer's Affected hosts section. The export drains the entire listing rather than the pages the table happened to load, de-duplicates by sensor, and reports truncation instead of passing a partial file off as complete.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOLRMM community rules render properly&lt;/strong&gt;: LOLRMM rules are plain Sigma YAML and now open in the Sigma detail view instead of falling through to the "Unable to parse rule content" raw fallback.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Entra ID adapter on Microsoft national clouds&lt;/strong&gt;: the Entra ID setup and edit forms gain the endpoint picker already offered by the Defender adapter, so a US Government tenant (GCC High, DoD) can be configured. The field is optional and omitted when unset, so existing commercial adapters are untouched.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_1"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Values loaded into a creatable multi-select rendered as empty — every existing pattern on an Artifact Collection or File &amp;amp; Registry Integrity rule was invisible in the edit modal. Adding one pattern to a field that looked empty silently replaced all the pre-existing ones on save.&lt;/li&gt;
&lt;li&gt;AI Terminal state no longer bleeds between sessions: file upload and download cards stayed pinned to the session they happened in rather than appearing in every conversation, and switching sessions no longer carries over the composer draft, the retry prompt, the download bar or a stale "queued behind a blocked turn" notice. A freshly started session also no longer sits idle because an earlier session in the same tab already consumed an initial prompt.&lt;/li&gt;
&lt;li&gt;The permissions table no longer overflows the addon and extension editors' modals, where the Write column sat off-screen until the user scrolled sideways.&lt;/li&gt;
&lt;li&gt;Opening an app that has been deleted from a stale link now shows a "not found" zero state with a route back to the launcher instead of a load failure, and a malformed link no longer crashes the render.&lt;/li&gt;
&lt;li&gt;Artifact Collection with no configuration saved yet reads as "no rules yet" instead of reporting an error.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 6.1.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-610</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-08-13:release/web-app-6-1-0</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Several UX improvements, new remediation signal (SLA due dates, root-cause roll-ups, coverage honesty), updated UX for some extensions, and performance improvements for Query Console.&lt;/p&gt;
&lt;h4 id="new-features_4"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud Security speaks one language&lt;/strong&gt;: every remaining screen — Inventory (Resources and Third-party assets), Attack Surface, Access, the Query Console, Compliance, Policies, Settings and the &lt;abbr title="Managed Security Services Provider"&gt;MSSP&lt;/abbr&gt; fleet board — now opens on the shared tinted filter bar.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compliance report layout&lt;/strong&gt;: the Compliance screen becomes a charts-and-rail report — a compliance-score donut and a failures-by-severity bar chart side by side, the controls table beneath them, and the assignment cards as a rail running down beside all three.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud Security fleet board modernized&lt;/strong&gt;: &lt;code&gt;/cloud-security&lt;/code&gt; adopts the UI language, adds two fleet rollup donuts, makes every column header a sort control, and splits freshness into sortable Last scan and Providers columns so a failing provider count is its own column rather than a badge in someone else's cell.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SLA due dates on the findings worklist&lt;/strong&gt;: findings gain a Due column showing relative age ("in 6d", "12d ago", "today"), with a tooltip carrying the exact deadline, the SLA state, and the policy clause that set it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Root-cause roll-ups on findings&lt;/strong&gt;: when one finding's remediation already implies another, the child shows a "root cause" chip that links straight to its parent and the parent shows how many findings it implies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Compliance score honesty&lt;/strong&gt;: a framework that grades only a fraction of its controls no longer shows a bare green score. The score loses its good-result tint and states how much was actually assessed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability-source coverage&lt;/strong&gt;: the Coverage tab adds a second dimension beside sensor coverage — whether anything is actually reporting CVEs on a workload — computed per scanner scope, so a workload with a sensor but no vulnerability source no longer reads as fully covered.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real internet entry points in the kill chain&lt;/strong&gt;: the first hop now renders the actual front door — App Service, Cloud Run URL, Kubernetes API server, function URL, load balancer, CDN, AI inference endpoint — labelled with its hostname, instead of a generic globe that said nothing about how an attacker got in.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Privilege escalation and cloud hierarchy in Topology&lt;/strong&gt;: scope-escalation hops render as their own edge category with a distinct signature and priority on a crowded canvas, and cloud-hierarchy containers (organization, folder, project, account) draw as containers rather than workloads.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Amazon Web Services"&gt;AWS&lt;/abbr&gt; boundary and trust evidence&lt;/strong&gt;: permission boundaries, boundary-capped grants and trust-policy conditions on can-assume edges now have a screen, and a finding's cloud is read from the finding itself so vulnerability-coverage aggregates keep their cloud badge and readable resource name.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dedicated &lt;abbr title="In LimaCharlie, Exfil (Event Collection) is a configuration extension that determines which types of events are collected and sent from endpoint agents to the cloud. It controls the data flow, ensuring only specified events are transmitted for monitoring and analysis. To capture specific events,..."&gt;Event Collection&lt;/abbr&gt; page&lt;/strong&gt;: &lt;code&gt;ext-exfil&lt;/code&gt; replaces the generic schema-driven form with a first-class page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dedicated Artifact Collection page&lt;/strong&gt;: &lt;code&gt;ext-artifact&lt;/code&gt; gains a custom made UI page with Collection Rules and PCAP Capture Rules tabs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dedicated Reliable Tasking page&lt;/strong&gt;: &lt;code&gt;ext-reliable-tasking&lt;/code&gt; moves off the generic schema renderer onto a custom page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The shared filter bar reaches the rest of the app&lt;/strong&gt;: the Platform Logs audit tab, False Positive Rules, and the sensor Vulnerabilities tab all move onto the same panel. The sensor Vulnerabilities tab's four bordered summary tiles become stats on the bar, and the Payloads list moves onto the standard table so dates and sizes stop wrapping.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;New Org and Recent Org lists for everyone&lt;/strong&gt;: the redesigned organization and recent-organization lists are now the default for all users.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Query Console performance&lt;/strong&gt;: a search over a large result set now completes much faster, holds less memory and spends less time in garbage collection. Scrolling with a row selected is more performant, and result sets that previously exhausted the browser's heap now load.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Connect wizard permissions&lt;/strong&gt;: the provider setup flow's "Permissions required" list now includes the &lt;abbr title="Amazon Web Services"&gt;AWS&lt;/abbr&gt; Organizations policy reads and the &lt;abbr title="Google Cloud Platform"&gt;GCP&lt;/abbr&gt; Cloud Run / Cloud Functions viewer roles, so a customer following the least-privilege list verbatim gets the public-invoker exposure verdicts rather than silently missing them.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_3"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;A single transient failure while polling for search results — a 502, a dropped connection, a laptop changing networks — permanently ended the search with no explanation; polling now survives it and picks the query back up.&lt;/li&gt;
&lt;li&gt;Returning to the Query Console tab after a network reconnect silently re-ran a finished search as a brand new server-side scan, replacing the results on screen and billing the org a second time.&lt;/li&gt;
&lt;li&gt;A crash affecting dropdown menus ("Maximum update depth exceeded") caused by an upstream &lt;code&gt;react-select&lt;/code&gt; bug is fixed.&lt;/li&gt;
&lt;li&gt;The Cloud Security "Failed" sync badge showed the collector error only as hover text that could not be selected or copied; the tooltip now stays open and the badge copies the raw error to the clipboard.&lt;/li&gt;
&lt;li&gt;The Vulnerabilities tab and section no longer appear on a sensor's detail view for organizations not subscribed to vulnerability reporting, where they showed a misleading empty "0 findings" report.&lt;/li&gt;
&lt;li&gt;The CAASM coverage-policy editor offered a capability no source could satisfy, which produced a permanent coverage gap on every device; it is removed from the picker, and policies that already contain it render as unsupported instead of blank.&lt;/li&gt;
&lt;li&gt;SOPs and &lt;abbr title="In LimaCharlie, an Organization represents a tenant within the Agentic SecOps Workspace, providing a self-contained environment to manage security data, configurations, and assets independently. Each Organization has its own sensors, detection rules, data sources, and outputs, offering complete..."&gt;Organization&lt;/abbr&gt; Notes had no working "View Docs" link, and their editors called records "Sop" and "Org_notes"; both now link to the published documentation and use proper record type names.&lt;/li&gt;
&lt;li&gt;The Inventory resource count rendered unformatted (&lt;code&gt;373109 assets&lt;/code&gt;) while every other count on the screen used thousands separators, and a shared accessibility defect meant several dropdowns' labels were not associated with their control.&lt;/li&gt;
&lt;li&gt;The "&lt;abbr title="Endpoint Detection &amp;amp; Response"&gt;EDR&lt;/abbr&gt; everywhere" policy template button appeared to do nothing due to a read-after-write bug, and a full-screen empty state could swallow clicks on neighbouring controls.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 6.0.2</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-602</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-07-29:release/web-app-6-0-2</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;A rebuilt Cloud Security Risks triage table, finding ownership as a filter and column, a self-serve Cloud Security upgrade flow, and a reorganized sidebar.&lt;/p&gt;
&lt;h4 id="new-features_6"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud Security Risks — dense triage worklist&lt;/strong&gt;: the card-per-finding list is now a ruled, sortable table at roughly twice the row density, a sticky header, server-side sorting on Risk and Severity, and select-all in the header checkbox so the bulk triage bar only appears once you pick rows. Multiple UX improvements related to this change.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Owner facet and column on Risks&lt;/strong&gt;: findings can now be filtered and scanned by who owns them. An Owner group in the facet rail lists Unassigned first, then your own account marked "(you)", then everyone else by count.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data Security matches the Risks layout&lt;/strong&gt;: the Data Security screen adopts the same tinted filter bar, flat facet rail and badge styling as the Risks worklist.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self-serve Cloud Security upgrade&lt;/strong&gt;: free-tier orgs can now upgrade without leaving the page. The trial band's CTA on the Cloud Security Overview opens an in-context upgrade modal that explains what upgrading changes, quotes the real monthly price for your org, collects payment details only if there's no card on file, and confirms on completion.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SOPs and &lt;abbr title="In LimaCharlie, an Organization represents a tenant within the Agentic SecOps Workspace, providing a self-contained environment to manage security data, configurations, and assets independently. Each Organization has its own sensors, detection rules, data sources, and outputs, offering complete..."&gt;Organization&lt;/abbr&gt; Notes move to &lt;abbr title="In LimaCharlie, an Organization represents a tenant within the Agentic SecOps Workspace, providing a self-contained environment to manage security data, configurations, and assets independently. Each Organization has its own sensors, detection rules, data sources, and outputs, offering complete..."&gt;Organization&lt;/abbr&gt; Settings&lt;/strong&gt;: both sidebar entries move out of Automation — where they sat next to &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt; rules, playbooks and lookups — into the &lt;abbr title="In LimaCharlie, an Organization represents a tenant within the Agentic SecOps Workspace, providing a self-contained environment to manage security data, configurations, and assets independently. Each Organization has its own sensors, detection rules, data sources, and outputs, offering complete..."&gt;Organization&lt;/abbr&gt; Settings group after Integrations, with matching breadcrumbs. Existing links and bookmarks to /sops and /org-notes still work.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apps entry always visible in the sidebar&lt;/strong&gt;: the Apps navigation item no longer disappears for users lacking the app.get permission; it renders for everyone and the page itself explains the missing permission when opened.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_5"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;The "Cloud Security isn't enabled" screen sent its main button to the extension's configuration page, which has no way to subscribe and often showed a permission wall; it now goes to the marketplace entry where the extension can actually be subscribed, and the button reads "View extension".&lt;/li&gt;
&lt;li&gt;Cloud Security still described itself as pre-GA and not publicly subscribable in the not-enabled gate and the feedback modal, even though it is generally available and self-serve.&lt;/li&gt;
&lt;li&gt;The Risks lens picker showed an empty "Select..." whenever the active class filters didn't match a preset lens, making it look like no lens was applied while a filter was in fact active; it now reads "Custom".&lt;/li&gt;
&lt;li&gt;Cloud resources were classified by their name, so a load balancer called "public-lb" was drawn as the internet node and a VM called "db-1" was drawn as a data store; classification now uses the resource's actual type. Similarly, an IAM principal named something like "public-reports@..." was labelled "Public - anyone on the internet".&lt;/li&gt;
&lt;li&gt;The fleet board's top attack path card navigated to a retired URL and silently bounced users to the org Overview; it now opens the Attack Surface workspace, and old bookmarked path links redirect there too.&lt;/li&gt;
&lt;li&gt;Third-party assets and reconciled inventory assets both displayed as "Third-party asset" in the graph type filter and node labels; inventory assets now read "Inventory asset".&lt;/li&gt;
&lt;li&gt;The shared-fix strip and the "resolves N findings" count only considered one kind of root cause, so privilege-escalation causes never appeared and mixed causes were counted twice — the strip and the finding detail card could disagree on the same fix. The shared-fix card also described every cause as a firewall rule, even when the fix was an IAM role binding.&lt;/li&gt;
&lt;li&gt;Sortable Risk and Severity column headers rendered a truncated "..." because the label plus the sort icon didn't fit their track.&lt;/li&gt;
&lt;li&gt;In dark mode, Risks table rows swallowed their own dividers and the header band.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 6.0.1</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-601</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-07-28:release/web-app-6-0-1</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;A small fix to the Cloud Security onboarding sign-up flow.&lt;/p&gt;
&lt;h4 id="bug-fixes_7"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Signing up from a Cloud Security onboarding link still asked which product you wanted before creating an account, even though the link had already committed you to one.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 6.0.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-600</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-07-27:release/web-app-6-0-0</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Cloud Security goes generally available, a one-link self-serve onboarding flow, and a rebuilt Cloud Security Overview dashboard.&lt;/p&gt;
&lt;h4 id="new-features_8"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud Security is generally available&lt;/strong&gt;: the product is no longer gated behind an early-access flag, so every organization with the Cloud Security extension sees it in the sidebar.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self-serve onboarding link&lt;/strong&gt;: a single shareable URL - &lt;code&gt;/onboard?purpose=cloud-security&lt;/code&gt; - now takes someone from no account to a working organization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud Security Overview rebuilt&lt;/strong&gt;: the Overview now uses the same flat dashboard language as the Case Management dashboard.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Full-screen kill-chain view&lt;/strong&gt;: the most-critical-path tile gains a "View full screen" action.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Trial status on the Overview&lt;/strong&gt;: organizations on the Cloud Security trial now see a banner at the top of the Overview stating the provider-connection cap and how many are used, the trial length, and a "See plans" link — instead of only finding out when they hit the limit.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Provider-aware connect wizard diagram&lt;/strong&gt;: the diagram in the provider setup wizard now draws what the provider you selected actually contributes — compute, network, data, identity, AI and vulnerability coverage for a cloud, or identities, apps and devices for a directory — and labels the credential path with how that provider authenticates (IAM roles, AssumeRole, GitHub App, and so on). The edge into your workspace now states the sync cadence you just chose on that step.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_8"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;The Overview coverage bar read 100% in nearly every state, because it counted only sources that had already completed one sweep rather than the estate itself; it now reports accounts collecting, shows a real shortfall while a connected source has delivered nothing, and stays empty rather than showing 0/0 before the first scan lands.&lt;/li&gt;
&lt;li&gt;Privilege-escalation findings were drawn with an invented "Internet -&amp;gt; public exposure" entry hop and a rationale claiming an open attack path, even for identity-only findings that are not internet-reachable; the exposure claim is now only made when the backend asserts it, and entitlement hops are labelled "can assume" instead of "reaches".&lt;/li&gt;
&lt;li&gt;The generic rationale on some findings printed a bare category name such as "High ciem."; the three entitlement categories now spell out what they mean.&lt;/li&gt;
&lt;li&gt;Verifying your email during sign-up sent you to the organization list and lost the onboarding flow you started; the verification link now returns you exactly where you left off, and the original tab no longer sits on a stale "verify your email" card after verification completes.&lt;/li&gt;
&lt;li&gt;The choke-point sentence naming your crown-jewel resources appeared in English in every language; it is now translated across all locales.&lt;/li&gt;
&lt;li&gt;Creating a secret inline in the provider wizard labelled the name field "New secret (required)", which read as if it were the credential itself; it now says "New secret name". Providers that take a raw key (LimaCharlie, OpenAI, Anthropic) also show a bare-key placeholder instead of suggesting a JSON wrapper.&lt;/li&gt;
&lt;li&gt;The provider wizard and first-run artwork drew logos for internal resources on a provider LimaCharlie does not support; the illustrations no longer use them.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.14.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-5140</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-07-26:release/web-app-5-14-0</guid>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;A redesigned permissions editor, modernized Outputs and Artifacts experiences, and an "Overview" org diagram.&lt;/p&gt;
&lt;h4 id="new-features_9"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Permissions — grouped, read/write-aware editor&lt;/strong&gt;: the flat ~120-row permission lists become collapsible resource groups (collapsed by default, search auto-expands matches) with separate Read and Write bulk toggles per group.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Outputs — modernized list and dry-run testers&lt;/strong&gt;: the Outputs list moves to the modern sortable table. New "Test Transform" / "Test Template" modals dry-run expressions server-side against an editable sample event before saving, and a WebSocket output destination is now creatable from the UI.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Artifacts — modernized list and full-screen viewer&lt;/strong&gt;: the Artifacts list becomes a Detections-style table with a new full-screen record viewer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Org Overview diagram&lt;/strong&gt;: new "Overview" page with high level diagram.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search — full-data exports&lt;/strong&gt;: the query console download menu splits into "Visible columns" (CSV/Excel/HTML/PDF, mirroring the table) and "All fields" (NDJSON plus new CSV/Excel that export every flattened field of every event), so nested event details are no longer dropped from spreadsheet exports.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sign-up — Grid escape hatch&lt;/strong&gt;: the sign-up flow asks whether users want the full LimaCharlie platform or the AI-assisted Grid before choosing an auth method.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Entra ID adapter&lt;/strong&gt;: an optional &lt;code&gt;streams&lt;/code&gt; parameter (risk detections / sign-ins / audit logs) is exposed in the cloud adapter form and &lt;abbr title="Command-line Interface"&gt;CLI&lt;/abbr&gt; template, and USP sensor tiles gain per-type documentation links (starting with Entra ID / Azure AD / Office 365).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Extended localization&lt;/strong&gt;: extension pages for 10+ more extensions are now fully localized across all nine languages.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_9"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Permission checkboxes in the API-key, add-on, and extension editors updated the form value but never visually toggled after the grouped-editor rewrite; they now toggle correctly.&lt;/li&gt;
&lt;li&gt;Privileged permissions (&lt;code&gt;apikey.ctrl&lt;/code&gt;, &lt;code&gt;user.ctrl&lt;/code&gt;, &lt;code&gt;billing.ctrl&lt;/code&gt;) could be bulk-granted in one click via select-all in the API-key/extension/add-on editors; they must now be granted individually.&lt;/li&gt;
&lt;li&gt;A hidden HoverCard added a second window scrollbar on every page that used one, sliding the app under the sidebar when scrolled.&lt;/li&gt;
&lt;li&gt;The modal close button floated over scrolled content in tall modals (e.g. the Data Classification rule editor); it now pins to the content and scrolls with the header.&lt;/li&gt;
&lt;li&gt;The sidebar collapse caret was hidden and unclickable on tablet-width viewports because the fixed top navbar overran the sidebar rail.&lt;/li&gt;
&lt;li&gt;Sortable table column headers wrapped their sort icon onto a second line in narrow columns (e.g. the Sensors "Type" column).&lt;/li&gt;
&lt;li&gt;Long unbroken tokens (resource ids, base64 keys) overflowed the CAASM "What Changed" column.&lt;/li&gt;
&lt;li&gt;Opening a Data Classification rule authored via &lt;abbr title="Infrastructure as Code (IaC) automates the management and provisioning of IT infrastructure using code, making it easier to scale, maintain, and deploy resources consistently. In LimaCharlie, IaC allows security teams to deploy and manage sensors, rules, and other security infrastructure..."&gt;IaC&lt;/abbr&gt; could crash the item detail when a hand-authored rule carried non-string values; such values are now coerced safely.&lt;/li&gt;
&lt;li&gt;The Artifacts list sent Insight timestamps in milliseconds instead of seconds, breaking the feature once the API began rejecting out-of-range values.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.13.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-5130</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-07-15:release/web-app-5-13-0</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Expanded Vulnerability Reporting, a revamped audit log, a redesigned REST API section, and continued localization across the extension catalog.&lt;/p&gt;
&lt;h4 id="new-features_10"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability Reporting&lt;/strong&gt;: a new Vulnerable Packages tab (with a package drawer listing live affected hosts) and a "Group by application" toggle on per-host tables that collapses per-CVE rows to one line per application. Exports are stamped with org name and &lt;abbr title="In LimaCharlie, an Organization ID (OID) is a unique identifier assigned to each tenant or customer account. It distinguishes different organizations within the platform, enabling LimaCharlie to manage resources, permissions, and data segregation securely. The Organization ID ensures that all..."&gt;OID&lt;/abbr&gt;, gain a server-generated remediation-plan CSV and a vulnerable-packages CSV.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities dashboard polish&lt;/strong&gt;: the Packages table collapses like the other tabs, posture stats match the detail-panel strip, and the CVE and package detail sidebars cross-link to each other. The CISA KEV catalog now opens with the full filter parameters applied.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit log revamp&lt;/strong&gt;: the Platform Logs audit tab adds sensor, date-range, and event-type filters plus client-side origin/identity search, bidirectional infinite scroll ("Load newer events"), and a row detail panel with a scrollable JSON viewer of the raw record.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;REST API section redesign&lt;/strong&gt;: API Details becomes a compact definition card with hover-to-copy on API Root, &lt;abbr title="In LimaCharlie, an Organization ID (OID) is a unique identifier assigned to each tenant or customer account. It distinguishes different organizations within the platform, enabling LimaCharlie to manage resources, permissions, and data segregation securely. The Organization ID ensures that all..."&gt;OID&lt;/abbr&gt;, and Org JWT and a Swagger reference link. The User-Generated, Service-Managed, and Ingestion key tables move behind a segmented pill switcher showing one table at a time, with a contextual Create button and one-line dates.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EPP status dashboard&lt;/strong&gt;: the per-sensor EPP status page is redesigned as a status dashboard, with the metric tiles filled out and macOS status, product name, and not-subscribed states corrected on the &lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Overview EPP card.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI provider onboarding&lt;/strong&gt;: a &lt;abbr title="Command-line Interface"&gt;CLI&lt;/abbr&gt; escape hatch lets you configure AI providers not yet supported in the guided onboarding flow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Internationalization&lt;/strong&gt;: continued localization of the extension catalog - Artifact, binlib, reliable-tasking, EPP, dumper, integrity, feedback, exfil, atomic-red-team, govee, hayabusa, infrastructure, lookup-manager, and ~30 more extension pages are now translated across all nine locales.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_10"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Tooltips now render above modals instead of behind them.&lt;/li&gt;
&lt;li&gt;Cloud adapter forms now enforce required secret and number fields before submit.&lt;/li&gt;
&lt;li&gt;&lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Overview hides cards and chips that don't apply to adapters and USP sensors, long tags no longer blow out the Overview grid, and EPP status resolves instead of stalling on "Waiting for sync".&lt;/li&gt;
&lt;li&gt;A newly created hive record shows its GUID immediately, and User ID click-to-copy is restored on the account settings page.&lt;/li&gt;
&lt;li&gt;Workload Scanning last-scan stats are corrected (wire tolerance) with a richer Last Scan detail, and the "Findings closed" column in Top remediations is fixed. The CVE sidebar count stat is labelled "Findings" rather than "Impacted hosts".&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.12.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-5120</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-07-09:release/web-app-5-12-0</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;The console and Grid app are now fully localized in English, Español, 日本語, Français, Deutsch, Português, 한국어, Italiano, and Nederlands alongside redesigned sensor pages and per-sensor vulnerability report exports.&lt;/p&gt;
&lt;h4 id="new-features_12"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Internationalization&lt;/strong&gt;: the console and Grid app are fully localized in English, Spanish (Español), Japanese (日本語), French (Français), German (Deutsch), Portuguese (Português), Korean (한국어), Italian (Italiano), and Dutch (Nederlands). A Language Switcher in User Settings sets the preferred language per device.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Analytics dashboard&lt;/strong&gt;: the per-sensor Analytics page is rebuilt as a responsive card-grid dashboard with a single shared time-range selector, replacing the stack of full-width charts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Overview redesign&lt;/strong&gt;: identity, network, and system details are organized into grouped cards with inline status chips for connection, seal, network, and platform state. Seal and Isolate controls move into the page header, with the full pending/cancel state machine preserved.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search progress indicator&lt;/strong&gt;: the query console status line shows a live percent-scanned figure while a paginated query runs, with a hover tooltip listing batch, event, and data counts for the in-scope scan. Cancelled searches are now labelled "Cancelled" instead of "Complete!".&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Per-sensor Vulnerability Report export&lt;/strong&gt;: the &lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Vulnerabilities tab adds an Export report menu with PDF, HTML, Markdown, CSV, and Excel formats. Reports include a KPI summary strip, top remediation recommendations aggregated by package and fix version, and the full findings table (CVE, application, version, severity, score, LC Risk, EPSS %, KEV, fix version, first detected date).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Builder Program promo&lt;/strong&gt;: free-tier users periodically see a Builder Program offer (first 3 months free) in the console. The promo is limited to first-party LimaCharlie branding, shown at most once every 7 days, and suppressed permanently once a user expresses interest.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability tables: First Detected and Version columns&lt;/strong&gt;: both the sensor-level and org-level vulnerability tables add a sortable First Detected column (the date a vulnerability was first observed on the host, marking the start of the remediation clock) and a Version column showing the installed version of each vulnerable package. The version value also feeds the compliance CSV export, replacing a previously hardcoded blank.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities dashboard and CVE detail redesign&lt;/strong&gt;: the org Vulnerabilities page replaces the 2×4 KPI card grid with a compact posture strip, brings charts forward, and narrows the CVE list/detail gracefully on smaller viewports. The CVE detail gains a cleaner CVSS metric card and a full-width EPSS percentile meter with banded severity coloring.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Microsoft Defender adapter&lt;/strong&gt;: an optional Endpoint field targets Enterprise (Commercial), GCC, GCC High (L4), or DoD (L5) Microsoft cloud environments. Existing adapters continue to use the enterprise endpoint by default.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;SentinelOne adapter&lt;/strong&gt;: optional &lt;code&gt;site_ids&lt;/code&gt; and &lt;code&gt;account_ids&lt;/code&gt; fields scope ingestion to a single tenant of an MSP/partner console, and a &lt;code&gt;collect_agents&lt;/code&gt; toggle pulls all in-scope endpoints as individual sensors immediately rather than waiting for telemetry.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; sub-page tables&lt;/strong&gt;: Autoruns, Drivers, &lt;abbr title="In LimaCharlie, Exfil (Event Collection) is a configuration extension that determines which types of events are collected and sent from endpoint agents to the cloud. It controls the data flow, ensuring only specified events are transmitted for monitoring and analysis. To capture specific events,..."&gt;Event Collection&lt;/abbr&gt;, Packages, Users, Services, Integrity, and Processes migrate to the updated table component, gaining sortable column headers, truncation tooltips, and consistent viewport-fill height. &lt;abbr title="In LimaCharlie, Exfil (Event Collection) is a configuration extension that determines which types of events are collected and sent from endpoint agents to the cloud. It controls the data flow, ensuring only specified events are transmitted for monitoring and analysis. To capture specific events,..."&gt;Event Collection&lt;/abbr&gt; and Integrity rule chips move into per-row kebab menus, and several empty-state typos are fixed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Analytics charts&lt;/strong&gt;: all analytics charts across &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt; rules, False-Positive rules, Outputs, &lt;abbr title="Adapters serve as flexible data ingestion mechanisms for both on-premise and cloud environments."&gt;Adapter&lt;/abbr&gt; Analytics, VibeRails, Billing quota, and the Grid app are updated. Outputs and &lt;abbr title="Adapters serve as flexible data ingestion mechanisms for both on-premise and cloud environments."&gt;Adapter&lt;/abbr&gt; Analytics charts now display side by side with a single shared time-range selector.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_12"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;The "Create new App" button now works for orgs with zero apps; a transparent overlay was intercepting pointer events over the page header.&lt;/li&gt;
&lt;li&gt;Opening the AI Terminal no longer crashes the app with "Maximum update depth exceeded".&lt;/li&gt;
&lt;li&gt;Seal and isolate pending transition states now display correctly, so "Pending rejoin" and "Pending unseal" surface during the backend transition window instead of holding on "Isolated" or "Sealed".&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.11.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-5110</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-06-29:release/web-app-5-11-0</guid>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Expanded AI cost tracking adds spend breakdowns, &lt;abbr title="Managed Security Services Provider"&gt;MSSP&lt;/abbr&gt; chargeback, and a savings trend to the AI Usage page, now available in the main web app alongside deeper Vulnerabilities filtering and functional app egress.&lt;/p&gt;
&lt;h4 id="new-features_14"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI cost tracking&lt;/strong&gt;: the AI Usage page now offers 7/30/90-day ranges, a KPI strip (spend, investigations, cost per investigation, tokens), spend breakdowns by model and detection rule with per-investigation unit cost, per-tenant re-bill markup for &lt;abbr title="Managed Security Services Provider"&gt;MSSP&lt;/abbr&gt; chargeback in the CSV export, anomaly and trend indicators, and a savings trend chart. Sub-cent costs display adaptive precision instead of rounding to $0.00.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI Usage in the main web app&lt;/strong&gt;: the AI Usage view, previously Grid-only, is now reachable from the main web app sidebar under the AI group, gated by the &lt;code&gt;ai_agent.get&lt;/code&gt; permission.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities subscription gating&lt;/strong&gt;: orgs without the Vulnerability Reporting extension now see a subscribe call-to-action (for &lt;code&gt;billing.ctrl&lt;/code&gt; users) or an admin-contact prompt, replacing the misleading empty state.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities platform filtering&lt;/strong&gt;: the Platform facet now scopes the CVEs tab, and dashboard charts and KPI tiles update to reflect active Severity and Platform filters, with a caveat label when other filters can't be represented in the rollup.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities application grouping&lt;/strong&gt;: the host vuln table splits the combined column into sortable Application and CVE columns, grouping all CVEs for a package together; the org drawer defaults to application sort and the sensor tab keeps score sort.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerabilities false-positive feedback&lt;/strong&gt;: a per-finding "Report incorrect detection" action collects a structured reason and relays it to the product team, separate from the local mark-false-positive triage action.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Gmail adapter&lt;/strong&gt;: setup and edit forms for single-mailbox OAuth and Workspace service-account flows, with per-feed capability toggles, subject scoping, and masked managed-secret storage for service-account credentials.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ThreatLocker adapter&lt;/strong&gt;: Include Child Organizations scoping for parent API tokens and individual toggles for the Approval Requests, Unified Audit, and System Audit feeds.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Brand feature flags&lt;/strong&gt;: branded deployments can disable fleet billing, case management, automation SOPs, mini apps, and the AI terminal per deployment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Windows PowerShell installer&lt;/strong&gt;: the Windows install wizard leads with a copy-paste PowerShell one-liner using LimaCharlie's hosted install.ps1, mirroring the Linux curl installer, with the manual EXE/MSI tab still available.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search timing breakdown&lt;/strong&gt;: the per-stage timing breakdown is now on by default for all users.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Connectivity&lt;/strong&gt;: the Add &lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; panel now lists the org's webhook endpoint alongside the existing addresses, making firewall setup for cloud sensors and webhook adapters easier.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apps launcher icons&lt;/strong&gt;: apps now derive distinct icons from author emoji, required-permission prefixes, and other signals before falling back to the generic diamond.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Per-theme logos&lt;/strong&gt;: runtime configs support a dedicated dark-theme logo alongside the standard logo.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_15"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Apps declaring allowed_origins can now make third-party fetch() calls; apps load from a real HTTP origin with their own permissive floor CSP instead of inheriting the console's strict policy. The brokered lc.api path and app isolation are unchanged.&lt;/li&gt;
&lt;li&gt;Apps now open correctly on Grid, which previously failed with a sandbox handshake timeout.&lt;/li&gt;
&lt;li&gt;Creating a false-positive rule from a detection now names the draft from the detection (category and detect ID) instead of "Untitled-1".&lt;/li&gt;
&lt;li&gt;Deleting a REST API key now requires confirmation through a danger dialog, preventing accidental deletion that would break integrations.&lt;/li&gt;
&lt;li&gt;Replaying a &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt; rule with target: detection now runs against the detection stream instead of the event stream, which had matched nothing.&lt;/li&gt;
&lt;li&gt;Projection queries that select &lt;code&gt;ts&lt;/code&gt; without an alias now show the column, formatted as YYYY-MM-DD HH&lt;img alt="🇲🇲" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@16.0.1/assets/svg/1f1f2-1f1f2.svg" title=":mm:" /&gt;ss in the table and exports.&lt;/li&gt;
&lt;li&gt;Saved query text can now be edited in the Edit Query modal, not just renamed.&lt;/li&gt;
&lt;li&gt;The saved-query size limit now matches the backend's 1024-byte ceiling, raised from a stricter 512-byte client cap.&lt;/li&gt;
&lt;li&gt;CVE descriptions from the NVD feed now render as sanitized HTML instead of literal tag text on the CVE detail page and sidebar drawer.&lt;/li&gt;
&lt;li&gt;The CVE detail page layout is now stable, with stacked tables sized to their actual row count instead of growing unboundedly or leaving large empty gaps.&lt;/li&gt;
&lt;li&gt;The KEV and Total vulnerability tiles now use server-computed host-wide counts instead of page-limited values, fixing incorrect counts for sensors with many findings.&lt;/li&gt;
&lt;li&gt;The create-case org picker now shows all cases-enabled orgs for accounts spanning more than 200 orgs, resolving names for up to 10,000 orgs.&lt;/li&gt;
&lt;li&gt;Social share previews are fixed for Grid and the main web app, with OG and Twitter tags added and robots.txt updated to allow social crawlers while keeping the console out of search indexes.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.10.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-5100</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-06-18:release/web-app-5-10-0</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Fleet Billing arrives for MSSPs, alongside AI Terminal refinements and clearer session-state reporting.&lt;/p&gt;
&lt;h4 id="new-features_15"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Fleet Billing&lt;/strong&gt;: a cross-tenant billing console for MSSPs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI Terminal&lt;/strong&gt;: visual improvements and refined landing actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI session statuses&lt;/strong&gt;: Running, Waiting, and Ended states, with an indicator when a session is awaiting user input.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Access Management&lt;/strong&gt;: added a Role column to the user table.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Case console&lt;/strong&gt;: added a selectable page size.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_16"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Query console download now matches the visible table.&lt;/li&gt;
&lt;li&gt;Added a Minimize button to the AI Session chat floating button.&lt;/li&gt;
&lt;li&gt;Added the AI Session chat button to the sessions page.&lt;/li&gt;
&lt;li&gt;Restored the "Download file from session" action in the chat menu.&lt;/li&gt;
&lt;li&gt;Restored the app version and release notes in the profile menu, and fixed the Dark Mode font.&lt;/li&gt;
&lt;li&gt;Adjusted the light-mode AI Terminal card fill color for better contrast.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.9.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-590</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-06-11:release/web-app-5-9-0</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Notable improvements and fixes:&lt;/p&gt;
&lt;h4 id="new-features_16"&gt;New Features&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI Terminal ShareCard&lt;/strong&gt; — share sessions socially and invite users to tenants.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Docked corner chat&lt;/strong&gt; — persistent AI chat launcher with pop-out, draft-new-session, minimize/maximize, and a live-session selector.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Session fork&lt;/strong&gt; — fork an AI session with full lineage tracking.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Card-list session browser&lt;/strong&gt; inside the chat layout with a unified action dropdown.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Onboarding demand-signal cards&lt;/strong&gt; for unsupported AI providers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Feedback rich card&lt;/strong&gt; plus unsupported-request guidance for the AI FDE.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ThreatLocker&lt;/strong&gt; platform and adapter support.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI Workbench&lt;/strong&gt; — agent usage moved into a dedicated Usage tab.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search&lt;/strong&gt; — scroll-to-top/bottom buttons, perceived + server timing on the status line, and query ID in the timing breakdown tooltip.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI Sessions&lt;/strong&gt; — rationalized session user state (Active + needs-attention), and &lt;code&gt;lc-compliance&lt;/code&gt; as a selectable plugin.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Git Sync&lt;/strong&gt; — added missing config hives to the UI.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id="bug-fixes_17"&gt;Bug Fixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed dark-mode LimaCharlie logo visibility.&lt;/li&gt;
&lt;li&gt;Included &lt;code&gt;ai_agent.operate&lt;/code&gt; in FDE and worker-key permission lists.&lt;/li&gt;
&lt;li&gt;Cases — batched bulk assign / tags / close-note to avoid rate-limit failures.&lt;/li&gt;
&lt;li&gt;Restored the agent list table in the AI Agents tabs.&lt;/li&gt;
&lt;li&gt;CVE detail now opens from the sensor vulnerability list.&lt;/li&gt;
&lt;li&gt;Timestamp column hidden for aggregation search results.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.5.5</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-555</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2026-02-08:release/web-app-5-5-5</guid>
      <pubDate>Sun, 08 Feb 2026 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Enhancements to the AI Sessions experience with granular permission controls and improved session management, adds Windows ARM64 sensor support for customers on newer Windows hardware, introduces search customization features including drag-and-drop column reordering and improved time range displays, and streamlines the sensor installation workflow with better Docker instructions and installation key visibility. The release also includes important security improvements for OAuth authentication and API key isolation between environments.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI Sessions&lt;/strong&gt;: Granular permissions, pagination, SOPs enabled&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Windows ARM64&lt;/strong&gt;: New sensor support for ARM-based Windows devices&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search&lt;/strong&gt;: Drag-and-drop columns, column popover, improved time display&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Investigation Viewer&lt;/strong&gt;: Major overhaul with new sidebar and unified data handling&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Installation&lt;/strong&gt;: Better Docker instructions, fixed modal behavior&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security&lt;/strong&gt;: Environment-specific API keys, GitHub OAuth trust, CSP fixes&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 5.2.1</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-521</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-10-24:release/web-app-5-2-1</guid>
      <pubDate>Fri, 24 Oct 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;A good batch of bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 5.2.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-520</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-10-17:release/web-app-5-2-0</guid>
      <pubDate>Fri, 17 Oct 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;&lt;strong&gt;Features:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Show errors "in place" for Outputs, Detections, and &lt;abbr title="LimaCharlie Extensions allow users to expand and customize their security environments by integrating third-party tools, automating workflows, and adding new capabilities. Organizations subscribe to Extensions, which are granted specific permissions to interact with their infrastructure. Extensions..."&gt;Extensions&lt;/abbr&gt; to accelerate troubleshooting&lt;/li&gt;
&lt;li&gt;Support text data types in extensions (e.g. for large inputs, per community request)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Bug fixes:&lt;/strong&gt; Query console, &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt; rule creation flow, Console, File system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 5.1.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-510</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-10-13:release/web-app-5-1-0</guid>
      <pubDate>Mon, 13 Oct 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Substantial update of Access Management for clarity and convenience of user management. Continued refinement of the UX for user and group management.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bug fixes:&lt;/strong&gt; Artifact list, file system, and more.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 5.0.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-500</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-09-30:release/web-app-5-0-0</guid>
      <pubDate>Tue, 30 Sep 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;The Query Console is now in the new UI theme. Feature-rich search and analytic capabilities integrated with the rest of the LimaCharlie platform marks a major revision.&lt;/p&gt;
&lt;div class="admonition note"&gt;
&lt;p class="admonition-title"&gt;Note&lt;/p&gt;
&lt;p&gt;The Query Console remains in beta while we continue to improve performance and refine usability.&lt;/p&gt;
&lt;/div&gt;</description>
    </item>
    <item>
      <title>Web App v4.5.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v450</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-09-12:release/web-app-v4-5-0</guid>
      <pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Many bug fixes and some ongoing UX improvements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.4.9</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-449</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-08-28:release/web-app-4-4-9</guid>
      <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;ul&gt;
&lt;li&gt;Improved UX for Access Management and Adapters pages&lt;/li&gt;
&lt;li&gt;Add Wiz cloud sensor adapter integration&lt;/li&gt;
&lt;li&gt;Many fixes and smaller improvements&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 4.4.4</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-444</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-07-18:release/web-app-4-4-4</guid>
      <pubDate>Fri, 18 Jul 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;A patch release with minor bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.4.3</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-443</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-07-10:release/web-app-4-4-3</guid>
      <pubDate>Thu, 10 Jul 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Fixed regression with sensor timeline view.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.1.2</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-412</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-06-27:release/web-app-4-1-2</guid>
      <pubDate>Fri, 27 Jun 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Bug fixes for customers and community.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.4.0</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-440</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-06-17:release/web-app-4-4-0</guid>
      <pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI-powered community rules (Beta)&lt;/strong&gt;: Easy way to turn thousands of community rules into LimaCharlie detection &amp;amp; response rules.&lt;/li&gt;
&lt;li&gt;New and improved &lt;abbr title="LimaCharlie Extensions allow users to expand and customize their security environments by integrating third-party tools, automating workflows, and adding new capabilities. Organizations subscribe to Extensions, which are granted specific permissions to interact with their infrastructure. Extensions..."&gt;Extensions&lt;/abbr&gt; page&lt;/li&gt;
&lt;li&gt;Bug fixes, including a few around auto-generated &lt;abbr title="LimaCharlie Extensions allow users to expand and customize their security environments by integrating third-party tools, automating workflows, and adding new capabilities. Organizations subscribe to Extensions, which are granted specific permissions to interact with their infrastructure. Extensions..."&gt;Extensions&lt;/abbr&gt; UI for extension builders&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 4.3.3</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-433</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-05-30:release/web-app-4-3-3</guid>
      <pubDate>Fri, 30 May 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;AI-assisted detection read-out, navigation improvements, showing org selector consistently, and a number of bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.3.2</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-432</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-05-22:release/web-app-4-3-2</guid>
      <pubDate>Thu, 22 May 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Fixes for a few edge-case crashes and recently reported bugs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.3.1</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-431</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-05-20:release/web-app-4-3-1</guid>
      <pubDate>Tue, 20 May 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;UI support for Endpoint Protection solution, bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.2.8</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-428</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-05-08:release/web-app-4-2-8</guid>
      <pubDate>Thu, 08 May 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;A number of UI bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.2.3</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-423</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-04-18:release/web-app-4-2-3</guid>
      <pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Fixing the artifact download broken in some cases, and other small bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.2.1</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-421</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-04-11:release/web-app-4-2-1</guid>
      <pubDate>Fri, 11 Apr 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AI co-writer for &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt;&lt;/strong&gt;: Use "ask AI" when creating a rule and it helps you write a detection and response based on your prompt. Currently uses Google's Gemini 2 Flash model tuned for LimaCharlie &lt;abbr title="Detection &amp;amp; Response"&gt;D&amp;amp;R&lt;/abbr&gt; rules. Standard AI disclaimer applies: "trust but verify."&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Event Tree&lt;/strong&gt;: Updated for usability and performance on giant trees. Enjoy collapsing and expanding groups of events, and traverse the tree with no strain on your browser.&lt;/li&gt;
&lt;li&gt;Other performance optimizations and bug fixes&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App 4.1.4</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-414</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-03-28:release/web-app-4-1-4</guid>
      <pubDate>Fri, 28 Mar 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;UI betterment: quick filters for common platforms on the &lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; list, reliable navigation from/to Detections, other small improvements and bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App 4.1.1</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-411</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-03-28:release/web-app-4-1-1</guid>
      <pubDate>Fri, 28 Mar 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Usability improvements on Detection page, ability to re-run command in sensor console, fix "copy array index," and numerous bug fixes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App v4.0.2</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v402</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-03-14:release/web-app-v4-0-2</guid>
      <pubDate>Fri, 14 Mar 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;ul&gt;
&lt;li&gt;A long-awaited modernized UI is available (in preview). More work is on the way to further improve user experience.&lt;/li&gt;
&lt;li&gt;In-product dashboards available (in preview): a bird's eye view on key detections and the flow of data.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is not just a paint job: we made substantial internal changes and will continue to improve quality.&lt;/p&gt;
&lt;div class="admonition note"&gt;
&lt;p class="admonition-title"&gt;Note&lt;/p&gt;
&lt;p&gt;On large orgs, the dashboards can take up to 15 seconds to load the very first time, and normalize after the first load. Optimizations are on the way.&lt;/p&gt;
&lt;p&gt;The Query Console is not available in the Modern UI yet. We will bring it there in a much better shape. In the meantime, switch back to the Old Theme to access it.&lt;/p&gt;
&lt;/div&gt;</description>
    </item>
    <item>
      <title>Web App v3.10.1</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v3101</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-02-28:release/web-app-v3-10-1</guid>
      <pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;ul&gt;
&lt;li&gt;Introduce Event Latency (&lt;code&gt;routing/latency&lt;/code&gt;), and add latency metrics to &lt;abbr title="Similar to agents, Sensors send telemetry to the LimaCharlie platform in the form of EDR telemetry or forwarded logs. Sensors are offered as a scalable, serverless solution for securely connecting endpoints of an organization to the cloud."&gt;Sensor&lt;/abbr&gt; Analytics, to help identify and troubleshoot event latency issues&lt;/li&gt;
&lt;li&gt;Add "Search by Description" to the org list&lt;/li&gt;
&lt;li&gt;Bug fixes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report a Bug&lt;/strong&gt;: Integrated tool to report bugs easily&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App v3.9.3</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v393</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-02-21:release/web-app-v3-9-3</guid>
      <pubDate>Fri, 21 Feb 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;Bug fixes: handling edge-cases of org creation and adding users flows, fixing MS 365 sensor false status in certain rare conditions, other small fixes and internal instrumentation improvements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web App v3.8.12</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v3812</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-01-24:release/web-app-v3-8-12</guid>
      <pubDate>Fri, 24 Jan 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;&lt;strong&gt;New Features:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;New Australia Datacenter&lt;/strong&gt;: Added a new datacenter in Australia to enhance performance and availability for users in the region.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secrets Manager Integration&lt;/strong&gt;: The SMTP password field now allows integration with the secrets manager, providing a more secure way to handle authentication credentials.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;New &lt;abbr title="LimaCharlie Extensions allow users to expand and customize their security environments by integrating third-party tools, automating workflows, and adding new capabilities. Organizations subscribe to Extensions, which are granted specific permissions to interact with their infrastructure. Extensions..."&gt;Extension&lt;/abbr&gt;&lt;/strong&gt;: ext-nims allows you to send detections from LimaCharlie to NIMS via the Notion API.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Bug Fixes and Enhancements:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Autofill OTP&lt;/strong&gt;: The one-time password (OTP) field now properly auto-fills from password managers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User Permissions Warning&lt;/strong&gt;: A warning message has been implemented to notify users when revoking permissions for a user.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App v3.8.10</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v3810</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2025-01-09:release/web-app-v3-8-10</guid>
      <pubDate>Thu, 09 Jan 2025 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;&lt;strong&gt;Bug Fixes and Improvements:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where creating a new secret in a secret manager and changing cloud adapter configuration at the same time would not update the cloud configuration with the new secret.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Web App v3.8.8</title>
      <link>https://docs.limacharlie.io/10-release-notes/#web-app-v388</link>
      <guid isPermaLink="false">tag:docs.limacharlie.io,2024-12-12:release/web-app-v3-8-8</guid>
      <pubDate>Thu, 12 Dec 2024 00:00:00 GMT</pubDate>
      <category>web-app</category>
      <description>&lt;p&gt;&lt;strong&gt;New Features:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Introduced user-level saved queries for improved data management.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Bug Fixes and Improvements:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed the alignment of the "skip for now" text on the initial sensor onboarding screen during organization creation.&lt;/li&gt;
&lt;li&gt;Resolved an error related to empty extension configurations.&lt;/li&gt;
&lt;li&gt;Fixed a minor horizontal scroll issue on the sensors page.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the organization creation waiting room would display "missing permission errors" when opening the app.&lt;/li&gt;
&lt;li&gt;Minor enhancement on the input field for adding a user to your organization, where it will now show an error if the "add user" button is clicked without an email filled in.&lt;/li&gt;
&lt;li&gt;Updated various mentions of "Yara" to be all caps to reflect it being an acronym.&lt;/li&gt;
&lt;/ul&gt;</description>
    </item>
  </channel>
</rss>
