Changelog

All notable changes to Vulnotes are documented here.

July 31, 2026

Frontend v0.12.2Backend v0.12.2

Added

  • Client portal statistics: explore reports, findings, pentest effort, severity and remediation status by period, application type and category, with links into the matching reports and findings
  • Client portal branding: apply your company name, logo and primary color throughout the customer experience
  • Review changes: field-aware diffs make edits easier to understand, with quick controls to revert individual changes
  • Client portal planning now includes every report the customer can access
  • Client portal DOCX downloads are now rendered directly from the report preview

Changed

  • Client portal pages now use responsive full-width layouts, pagination and constrained customer views for easier navigation at any screen size
  • The client notification bell now lives in the sidebar footer

Security

  • Tamper-evident audit trail records who changed what across authentication, reports, findings, users, teams, roles, companies, API keys, invitations, settings and the client portal
  • Uploaded files now require authentication and resource-level authorization
  • Report rendering blocks JavaScript and unauthorized network requests while keeping report-owned images available
  • Password changes and resets now revoke every active session and access token
  • Open registration closes automatically after the first account is created
  • Webhook headers, secrets and element tokens are redacted from API responses
  • Client portal DOCX generation uses a restricted, authenticated internal rendering path