Changelog

Last updated: Oct 1, 2026


About this changelog

What this changelog shows

This changelog shows the new value that you get from the product. New value is a new function that you can use. Each changelog item tells you about one new function.

This changelog also shows deprecations. A deprecation is a function that Fluid Attacks removes from the product. Each deprecation item tells you about one function that you had before and do not have after the deprecation. Fluid Attacks shows a deprecation in the release in which it removes the function from the product.

What this changelog does not show

The product must be correct, fast, stable, secure, clear, and documented. The work that obeys these obligations is not new value. This changelog does not show:

  • Bug fixes. A bug is an error that Fluid Attacks made.
  • Cosmetic and text changes. Examples: a new logo, new colors, a new name for a section, a clearer message.
  • Changes that you cannot use. The changelog shows a change when you can use it.
  • Quality improvements. Examples: more performance, more availability, a migration to a different programming language.
  • Documentation improvements.
  • Security fixes to the product. When Fluid Attacks fixes a vulnerability in the product, you do not get a new function. But a new security function that you can use is new value, and the changelog shows it.
  • Internal changes. An internal change gives you the same functions. Examples are better logs for the support team, better records in the audit trail, and a data migration in a product database. A new supplier for a technology in the product is also an internal change.

Organization

This changelog has one page for each year. Each page shows the months of the year. Each month shows one or more releases. A release shows the changes that Fluid Attacks deployed in one week. The release number is the number of the week in the year. The most recent release is at the top of the page.

Modules

Each item starts with a module. The module tells you the part of the product that changed:

  • (SAST): the static analysis scanner
  • (AI SAST): the AI-assisted static analysis scanner
  • (DAST-WEB), (DAST-API): the dynamic analysis scanner
  • (MAST): the mobile application scanner
  • (SCA): the scanner for software composition analysis
  • (SS): the secrets scanner
  • (CS): the container scanner
  • (CSPM): the cloud security scanner
  • (Reachability): the reachability analysis
  • (ASPM): the platform at app.fluidattacks.com
  • (DB): the Database at db.fluidattacks.com
  • (API): the platform API
  • (IDE Plugin): the VS Code, Cursor, and IntelliJ IDEA extensions
  • (MCP): the MCP server
  • (CI Gate): the CI gate

On this page