Product changes

Release notes

Follow confirmed PurpleWASP product and documentation changes, including new capabilities, resolved issues, administrator actions and links to updated guidance.

Latest Microsoft Integration v1

Microsoft multi-capability integration completed and deployed on Linux

PurpleWASP now operates one shared Microsoft tenant connection with independently enabled Entra ID, Microsoft 365 Security, Intune, Defender for Endpoint and Azure capabilities. Entra, M365 Security and Azure have completed acceptance; Intune and Defender are implemented and await licensed-tenant validation.

New and improved
  • Added microsoft.m365_security, microsoft.intune_devices, microsoft.defender_endpoint and microsoft.azure_resources beneath the existing Microsoft provider/tenant connection.
  • Added independent per-capability enable/disable controls while preserving the Microsoft connection as the master authentication boundary.
  • Updated manual Run Sync and scheduled execution behaviour so disabled capabilities are not queued.
  • Added capability-specific readiness semantics so missing licences, tenant provisioning or Azure RBAC do not invalidate the shared Microsoft connection.
  • Validated Microsoft 365 Security Secure Score/control observations and Azure authentication/read probes on Windows and Linux.
  • Completed Linux deployment acceptance using the canonical Integration Management worker and scheduler/timer paths.
Resolved issues
  • Resolved stale long-running worker behaviour that could keep an older dispatcher map loaded after capability code changes.
  • Resolved Microsoft runtime credential-helper loading so shared encrypted credentials are available to capability collectors.
  • Prevented disabled Intune/Defender capabilities from being queued alongside enabled Microsoft capabilities.
Integration Management v1

Microsoft Entra ID and Qualys moved to the shared Integration Management runtime

PurpleWASP now operates Microsoft Entra ID v1 and Qualys through a shared Integration Management control plane with encrypted credentials, background jobs, normalized observations and downstream Asset/Control consumers.

New and improved
  • Completed Microsoft Entra ID v1 connection testing, Graph collection and normalized identity observations with required versus optional/licence-dependent evidence semantics.
  • Completed Qualys migration to Integration Management while retaining vulnerability-domain processing in Asset Management.
  • Added Integration Management worker and scheduler operation on Windows Task Scheduler and Linux systemd/timer.
  • Added automated Control test/evidence materialisation for adopted applicable Controls, including idempotency, evidence lifecycle and preserved provenance/history.
  • Standardised Integration Management operational timestamps on UTC and retained local-time display in the UI.
  • Removed the legacy Asset Management integration control-plane runtime and references after Windows/Linux cutover validation.
Resolved issues
  • Resolved legacy runtime-path dependencies between Qualys and Asset Management integration helpers.
  • Resolved mixed UTC/local MySQL runtime timestamps for Integration Management jobs/runs/capability state.
  • Resolved evidence-lifecycle re-preparation failures in the affected MySQL archive operation.
Resources update

Release notes added to PurpleWASP Resources

PurpleWASP Resources now includes a dedicated release-notes area so confirmed product and documentation changes can be recorded in one consistent, user-facing history.

New and improved
  • Added Release Notes as a first-class item in the Resources navigation.
  • Added a dedicated release history page with a consistent format for summaries, improvements, fixes, administrator actions and documentation links.
  • Separated release content from the page template so future releases can be added by updating a single release data file.
  • Added a Release Notes entry point to the main Resources page.
Resolved issues

No resolved issues were recorded for this release.

Verified changes only

Release notes are a production record. Planned or unverified work should not be published here.