Platform Updates
Release Logs
Track changes, security enhancements, and feature launches across all FintastIQ systems.
2026-09-15
v1.3.1
Latest Production StableFixed
- Release evidence is now pushed to TrustCloud on an actual release (a `v*` tag push or a published release) even when the target test already reports `up_to_date`. The freshness skip is a monthly-cron optimisation; on a release it suppressed exactly the evidence PDP-7 and PDP-8 exist to capture. The first genuine tag-triggered run for v1.3.0 exported a correct CSV (`TriggerRef=v1.3.0`, `TriggerEvent=push`) and uploaded nothing, because a manual dispatch six days earlier had left both tests `up_to_date`. Scheduled and manual runs keep the skip.
2026-09-15
v1.3.0
Latest Production StableAdded
- FintastIQ Talent and the GAP platform: public Our Talent section, autonomous candidate intake, role-based workspace, the GAP Match scoring engine with bids and a notification bell, consent-gated SMS, marketplace operations, and the GAP Community, Referral Program and Expert Partners sections.
- Zoho People personnel sync to the TrustCloud Hybrid Data Fabric, feeding automated HR and access-review evidence.
- Expanded automated evidence collection for SOC 2 and ISO 27001 coverage: GitHub Enterprise infrastructure-as-code and production-access exports, Zoho Vault password-manager evidence, a Zoho Sheet risk register export, security-scan evidence, a monthly AI vendor access review, and self-attestation evidence.
- Automated release-notes generation from merged pull requests, with an interactive release-notes page offering repository filtering and search.
- A quality gate on main - lint, tests and production build plus a separate dependency security scan - running on pull requests and pushes to main, with all checks blocking.
- Static application security testing and secret scanning in CI (Semgrep and Gitleaks) alongside a production dependency audit, on pull requests, pushes to main and a weekly schedule.
- Retry with jittered backoff for Aurora Serverless v2 Data API calls while a cluster resumes from auto-pause.
Changed
- Deploy workflows authenticate to AWS through GitHub OIDC web identity instead of a static IAM access key.
- The GitHub Enterprise evidence token is minted per run from a GitHub App installation, with the static personal access token retained as an automatic fallback.
- The release evidence bot fires only on published releases and on application release tags (v*); the shared UI library tag trigger was removed, and every exported evidence row now records its trigger ref, trigger event, source commit and export timestamp.
- Our Toolkit, Our Talent and GAP Workspace navigation entries are hidden behind launch flags; all routes remain live and directly linkable.
- Pinned TypeScript to 5.9.3, resolved a dependency override collision and closed the associated CVEs.
- Routine dependency updates across the application and workflow toolchain.
Fixed
- Evidence collection no longer reports success on partial or empty results: authentication failures in the two GitHub Enterprise exporters are fatal instead of being recorded as benign findings such as "branch protection Disabled" or "no Dependabot alerts"; safe() in the AWS exporter returns its declared default and the script exits non-zero with a per-control failure summary; and a post-collection check refuses to report success when a CSV is missing or trivial.
- Corrected the Zoho People record-fetch endpoint, moved the HR export onto Zoho People-scoped OAuth credentials, and made an empty employee roster fail rather than emit a header-only CSV.
- Bounded the OWASP ZAP full scan with a step timeout so a hanging optional scan can no longer cancel the job and skip the TrustCloud push, and made an unset ZAP scan target fail loudly.
- The Amplify deploy job is resolved by commit SHA with a bounded poll loop and an overall timeout, instead of adopting an arbitrary in-progress job.
- The TrustCloud personnel import negotiates an accepted line delimiter instead of sending a raw newline byte.
- TrustCloud control lookup, self-assessment evidence filtering and file-to-test mapping corrected; changelog regex parser and squash-merge release-notes extraction fixed.
- Permanent guards against the recurring cross-app login redirect loop, including a login-scoped middleware loop breaker with a user-facing recovery path.
- Resolved 215 ESLint problems exposed after the ESLint 10 crash fix, cast typed parameters in user_profiles queries for the RDS Data API, and collapsed multi-column grids on mobile so pages fit a 375px viewport.
Security
- Removed the long-lived static AWS access key from the deploy path in favour of short-lived OIDC credentials scoped to this repository.
- scripts/export_changelog.py no longer writes a hardcoded baseline CHANGELOG.md when the file is missing. A checkout or working-directory problem previously produced a fully provenance-stamped CSV of releases that were never read from the repository; it now fails the export instead.
2026-06-05
v1.2.0
Latest Production StableAdded
- Integrated automated Zoho Desk security incident tracking.
- Added running CHANGELOG.md parser to automate release notification evidence.
2026-06-01
v1.1.0
Latest Production StableAdded
- Automated GitHub Dependabot vulnerability scans extraction.
- Branch protection and automated pull request check workflows.
2026-05-15
v1.0.0
Latest Production StableAdded
- Initial deployment of FintastIQ dashboard.
