{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-changelog/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Synqly Release Notes 2026-09-18","siteUrl":"https://docs.synqly.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"release-notes---new-features--bug-fixes","__idx":0},"children":["Release Notes - New Features & Bug Fixes"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-email-security","__idx":1},"children":["📧 Email Security"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ New Provider"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add the Microsoft 365 Management Activity Email Security Provider, reading Exchange mail-send audit events from the Office 365 Management Activity API and emitting OCSF Email Activity (class ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["4009"]},"). Unlike the existing Exchange provider, this one carries file attachment metadata, separated ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["To"]},"/",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Cc"]},"/",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Bcc"]}," recipients, sender context, sensitivity labels, and delivery status. Supported on Global, GCC, GCC High, and DoD clouds, with either a client secret or an X.509 client-assertion certificate as the credential."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Because the Management Activity API is a subscription-based firehose, provider-side filtering is limited to the blob publication time (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["metadata.logged_time"]},"), not the time the message was sent, and each message produces two audit records — a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Send"]}," record carrying the message and its attachments, and a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MipLabel"]}," record carrying separated recipients and structured attachment metadata. The two are returned as they arrive rather than merged."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email.bcc"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email.actor"]}," to the Synqly OCSF 1.8.0 extension. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["bcc"]}," is typed as an array of email addresses, matching ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["cc"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["to"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Publish the Microsoft 365 Management Activity provider configuration guide, covering the Entra app registration, the two required Office 365 Management APIs application permissions, both credential types, and the Connect field table."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-network-security","__idx":2},"children":["🌐 Network Security"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Add AWS Route 53 Resolver query log support to the Network Security Connector, through two new operations: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /v1/network-security/dns/log-configurations"]}," discovers the query-log configurations an integration can read, returned as OCSF Cloud Resources Inventory Info (class ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["5023"]},"), and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /v1/network-security/dns/log-events"]}," returns normalized DNS events from those configurations as OCSF DNS Activity (class ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["4003"]},"). Both CloudWatch Logs and S3 destinations are supported, with time-range filtering and pagination. To scope an integration to specific configurations, set ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["dns_log_configuration_ids"]}," the same way ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["traffic_log_configuration_ids"]}," already works."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"️-edr-endpoint-detection--response","__idx":3},"children":["🛡️ EDR (Endpoint Detection & Response)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["🐛 Bug Fix"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Fix Microsoft Defender ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_edr_events"]}," skipping and repeating events across page boundaries when events share a timestamp. Defender routinely emits several events at the same millisecond, and paging on time alone left their relative order undefined, so a page boundary landing inside such a group lost some events and duplicated others. The event identifier is now applied as a secondary sort whenever ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["time"]}," is the requested ordering."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-endpoint-management","__idx":4},"children":["📦 Endpoint Management"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Add the standard ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["meta"]}," query parameter to the four device action endpoints — ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["update"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lock"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["restart"]},", and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["wipe"]}," — so ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://docs.synqly.com/api-reference/meta-functions"},"children":["meta functions"]}," work there as they do on every other engine endpoint. The request body schema, paths, and methods are unchanged, and callers that omit ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["meta"]}," see no difference in behavior. Go SDK consumers should note one rename: the request body type ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["DeviceActionRequest"]}," is now ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["DeviceActionRequestBody"]},". Only the Go type name changes; no request or response payload is affected."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-asset-management","__idx":5},"children":["📦 Asset Management"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Add ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /v1/assets/devices/{deviceUid}/software"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_device_software"]},") for per-device software inventory, implemented for Ivanti Neurons. Other Asset Management providers declare it unsupported and keep tenant-wide ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_software"]}," as-is."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["🐛 Bug Fix"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Stop advertising tenant-wide Query Software Inventory on Ivanti Neurons, which has no tenant-wide software list — software exists only on device records, so an unscoped ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GET /v1/assets/software"]}," could never succeed. Ivanti ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_software"]}," is now declared unsupported and returns ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["501"]}," when called without a device scope, instead of ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["400"]},". Existing callers filtering on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["device.uid[eq]"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["device.uid[in]"]}," keep working unchanged."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-vulnerability-management","__idx":6},"children":["🔍 Vulnerability Management"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add filters to the Pentera provider for parity with the other vulnerability providers: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.last_seen_time"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.last_seen_time_dt"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["gte"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["gt"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lte"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lt"]},") on Query Findings, and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["device.uid"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eq"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["in"]},") on Query Assets. Pentera's API accepts only a task-run ID, so these are applied by Synqly, and last-seen is aliased to the vulnerability creation time Pentera exposes."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Improve the Horizon3 NodeZero field mapping. CISA KEV status is now forwarded to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["vulnerabilities[].xattributes"]},", and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["is_exploit_available"]}," is set only when a finding is actually in the KEV catalog rather than defaulting to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["false"]}," on nearly every finding. NodeZero proof data is now shaped into ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.supporting_data"]}," — caption, command output, source URL, module, and collection time — while the raw record remains at ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["vulnerabilities[].xattributes.proofs"]},". ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.src_url"]}," is now set from the weakness portal URL on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_findings"]},", matching the other Horizon3 finding path, and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.xattributes"]}," is reachable as a typed field in the SDKs for OCSF 1.3.0, 1.4.0, and 1.6.0 instead of being dropped."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["🐛 Bug Fix"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fix Axonius silently truncating Query Findings and Query Assets walks. The next-page offset skipped one row per page and drifted ahead of the true row position, and the end-of-results check used Axonius's unfiltered page counts, which run ahead of a filtered result set and could end a walk early or hand back a cursor for a page that was already short. Paging now advances contiguously with no skipped or repeated rows, and a short page ends the walk."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fix Microsoft Defender EASM ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_findings"]}," returning no findings at all for workspaces containing ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["page"]}," assets. A ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["page"]}," asset's identifier embeds a full URL, and percent-escaping it into the request path left an escaped slash the Azure gateway rejects with a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["400"]}," before EASM saw the request — and because the asset walk stopped on the first error, one unencodable asset zeroed out findings for the entire workspace. Asset identifiers are now sent as base64url, and a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["400"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["404"]}," on a single asset is logged and skipped rather than ending the walk, while auth, throttling, and upstream faults still surface."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Stop advertising sort fields the connector cannot honor. The Vulnerabilities Connector rejects every order clause before the provider runs, so Microsoft Defender ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_assets"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["device.last_seen_time"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["device.hostname"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["device.os.name"]},") and Tenable.sc ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_findings"]}," (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["severity"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.first_seen_time"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["finding.last_seen_time"]},") advertised orderings that returned a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["400"]}," to any caller that followed capabilities. Those orderings have been removed from the published capabilities; query behavior is unchanged."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-application-security","__idx":7},"children":["🔐 Application Security"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["🐛 Bug Fix"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Fix HCL AppScan on Cloud Application Findings and Findings queries failing to transform when a finding carries a CVE ID but a null or empty CVSS score. The mapping errored while resolving ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["cvss.base_score"]}," instead of omitting it."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-identity-management","__idx":8},"children":["👤 Identity Management"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Add ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_risk_events"]}," to the PingOne Identity Provider, backed by PingOne Protect. Risk evaluations are read from audit activities, giving an auditable history with pagination, time filtering, and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["include_raw_data"]},", and are returned as OCSF Detection Finding (class ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2004"]},") with severity, user, source, and recommended action. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["query_risky_users"]}," is not supported on PingOne; the existing directory, user, group, and audit log operations are unaffected."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["🐛 Bug Fix"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fix Greenhouse Test Connection reporting a bad User ID as \"Invalid URL\" and blaming a field that does not exist. A typed ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401"]}," from the provider was being wrapped into an untyped ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["500"]}," before classification, so an authentication failure was reported as a configuration error; the error chain is now inspected for the typed failure first. This classification fix applies to every provider that wraps transport errors this way."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Accept either a numeric Greenhouse user ID or a full Greenhouse user URL in the User ID field, which is now labeled and documented with examples and client-side validation in Connect. A pasted URL is reduced to the numeric ID automatically, and an empty value remains valid."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-siem--sink","__idx":9},"children":["📊 SIEM & Sink"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Paginate Elasticsearch event queries over a Point-in-Time snapshot with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["search_after"]}," instead of a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["from"]}," offset. Events sharing a sort value — very common with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["@timestamp"]}," — could previously be returned twice or skipped between pages, and documents written mid-session shifted the offset window. The snapshot freezes the index for the whole pagination session and adds an automatic tiebreaker, so each event is returned exactly once in a stable order. Cursors issued before this release keep working, and an expired snapshot now returns a clear \"restart pagination\" error. Alert pagination, raw-body passthrough, and OpenSearch are unchanged."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Document how to update the Synqly Sentinel Solution and its data collection rule, based on troubleshooting with Microsoft support. The process is not as clean as we would like, but it is the best path currently available; we have asked Microsoft for a better workflow."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"️-core","__idx":10},"children":["⚙️ Core"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✨ Enhancement"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Derive OCSF enrichment from the compiled OCSF schema rather than a hand-maintained table, on CrowdStrike, Microsoft, OpenSearch, and AWS to start. Events from those providers now carry a complete, version-correct ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["observables[]"]}," array, enum sibling names (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["class_name"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["severity"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["status"]},", and the rest), and a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["metadata.profiles"]}," set reflecting the profiles the event actually exercises. Enrichment is strictly additive: hand-authored observables are preserved, an explicit profile declaration is never overridden, and every other provider is unchanged."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Restore OCSF base object fields that the legacy Synqly extension was dropping from the typed SDKs. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["resource_details"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["agent"]}," replaced their base OCSF definitions instead of extending them, discarding every attribute the frozen legacy copy did not redeclare — ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["agent.policies"]}," on all versions, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["resource_details.hostname"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tags"]}," at 1.4.0, and twelve more fields at 1.6.0. These now merge with the base objects, so fields such as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["resource_details.tags"]}," — already written on the wire by the AWS and Palo Alto cloud inventory providers — are reachable as typed fields. The change is additive only."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["🐛 Bug Fix"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Fix error responses being corrupted across unrelated requests. When a provider returned a shared package-level error value, the first request to reach it stamped its own integration context onto that shared value permanently, so later requests — on any integration, in any account — could receive the first request's integration ID, HTTP status, and problem type. The mutation was also unsynchronized, racing between concurrent requests. Errors are now copied before they are annotated."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Stop Pentera credentials reaching ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["api/response"]}," metadata and error parameters. The Pentera login response and the session token every data response carries at ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["meta.token"]}," were being recorded like any other provider call, so a caller requesting response metadata on a Pentera vulnerabilities call could receive a live credential. The login is now treated as a credential exchange and skipped by collection, and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["meta.token"]}," reads ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["REDACTED"]},". Separately, and for every provider, a failed credential exchange no longer reports its request or response body in error parameters or parse-error messages."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Refuse a private key pasted into a provider's certificate field, on both credential create and rotate. That field is stored unencrypted on the assumption that a certificate is public material. The audit trail obfuscator, which persists the request body of every credential write, also now matches ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["certificate"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["private_key"]},", so a certificate credential's private key no longer lands in the audit log verbatim."]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-sdk-releases","__idx":11},"children":["📚 SDK Releases"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Latest Versions"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Released Synqly SDK versions: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.56"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.57"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.58"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.59"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.60"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.61"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.62"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.63"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.64"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.65"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.0.66"]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"-synqly-embedded","__idx":12},"children":["🚢 Synqly Embedded"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Latest Release: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0.1.157"]}]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Service Image Tag"]},": ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["embedded-2026.09.18"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Service Image Tag (NO FIPS)"]},": ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["embedded-2026.09.18-no-fips"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Release Date"]},": September 18, 2026"]}]}]},"headings":[{"value":"Release Notes - New Features & Bug Fixes","id":"release-notes---new-features--bug-fixes","depth":1},{"value":"📧 Email Security","id":"-email-security","depth":1},{"value":"🌐 Network Security","id":"-network-security","depth":1},{"value":"🛡️ EDR (Endpoint Detection & Response)","id":"️-edr-endpoint-detection--response","depth":1},{"value":"📦 Endpoint Management","id":"-endpoint-management","depth":1},{"value":"📦 Asset Management","id":"-asset-management","depth":1},{"value":"🔍 Vulnerability Management","id":"-vulnerability-management","depth":1},{"value":"🔐 Application Security","id":"-application-security","depth":1},{"value":"👤 Identity Management","id":"-identity-management","depth":1},{"value":"📊 SIEM & Sink","id":"-siem--sink","depth":1},{"value":"⚙️ Core","id":"️-core","depth":1},{"value":"📚 SDK Releases","id":"-sdk-releases","depth":1},{"value":"🚢 Synqly Embedded","id":"-synqly-embedded","depth":1}],"frontmatter":{"seo":{"title":"Synqly Release Notes 2026-09-18"},"slug":"changelog/2026-09-18"},"lastModified":"2026-09-21T16:50:36.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/changelog/2026-09-18","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}