Recent releases for CASES 2022-08-16T04:08:18.087391+00:00 python-feedgen Fit4Cybersecurity v0.0.1 Fit4Cybersecurity v0.0.1 2019-10-22T14:42:03+00:00 - first public release of Fit4Cybersecurity. 2019-10-22T14:42:03+00:00 Fit4Cybersecurity v0.0.2 Fit4Cybersecurity v0.0.2 2019-11-13T07:25:45+00:00 ### Improvements - when nothing is clicked, the "Next" button should be gray (to show that you can't continue) [#1](; - when you have started the survey, and you click on the logo, the survey just ends without any warning or time to take the user ID. There should be at least a warning when clicking on the logo, or even the "Continue later" menu [#1]( ### Fixes - the Diagnostic contact form does not appear if you have more than 80 as a result [#1]( 2019-11-13T07:25:45+00:00 Fit4Cybersecurity v1.0.0 Fit4Cybersecurity v1.0.0 2019-11-25T08:22:07+00:00 ### Improvements - add country to the first question [#4](; - change language at any moment in the survey [#6](; - feedback Box in questions form and display the on review page [#7](; - add a general tool feedback form [#8](; - rename and move to the top "restore results" link [#9](; - change countries selector display style [#10]( 2019-11-25T08:22:07+00:00 Fit4Cybersecurity v1.0.1 Fit4Cybersecurity v1.0.1 2020-02-14T08:54:46+00:00 ### Changes - changed the minimum acceptable threshold to request a diagnostic to 65; - migrated to Django 3. 2020-02-14T08:54:46+00:00 TACOS v0.0.15 TACOS v0.0.15 2019-07-16T08:32:04+00:00 - first public alpha release of TACOS. 2019-07-16T08:32:04+00:00 TACOS v0.0.16 TACOS v0.0.16 2019-08-08T11:39:36+00:00 ### New - [games-and-quiz] a new game, 'Phishing ?', has been added; - [spam-signal] the permission READ_CALL_LOG for Android is no more required since the dependency to cordova-plugin-calllog has been removed; ### Enhancement - [core] improvements to the main menu and application logo; - [spam-signal] improvements to the layout; - [spam-signal] it is now possible to manually search for a phone number. 2019-08-08T11:39:36+00:00 TACOS v0.0.17 TACOS v0.0.17 2019-08-08T11:40:26+00:00 ### New - we added an agenda for the Cyber Security Week Luxembourg 2019. ### Enhancement - [core] improvements to the user interface (for Android and iOS); - [news] it is now possible to share a news via different social networks or applications from the device; - [core] translations were updated. 2019-08-08T11:40:26+00:00 TACOS v0.0.18 TACOS v0.0.18 2019-09-05T12:27:06+00:00 ### New - [core] a dark theme is now available for the interface. ### Enhancement - [games-and-quiz] an new example of phishing game has been added; - [core] the application now detects when the internet connection is lost. The management of the cache has been improved; - various improvements to the interface; - improvements to the translations. 2019-09-05T12:27:06+00:00 TACOS v0.0.19 TACOS v0.0.19 2019-09-05T12:27:31+00:00 - Android API level is now set to minimum 26 (android-minSdkVersion). 2019-09-05T12:27:31+00:00 TACOS v0.0.21 TACOS v0.0.21 2019-10-01T19:10:40+00:00 ### New - [spam-signal] the user has now possibility to report spam number in clear. This behavior is configurable in the settings of the application. - [games-and-quiz] added new quiz about WiFi. ### Enhancement - more tips and tricks are now available; - improvements to the dark theme. ### Fix - [settings] fixed a random bug when changing the value of SPAM_SEND_CLEAR (due to a infinite loop triggered via (ionChange)). 2019-10-01T19:10:40+00:00 TACOS v0.0.22 TACOS v0.0.22 2019-10-02T13:18:54+00:00 ### Enhancement - improvements to the dark mode; - improved display of the games and quiz section; - android-targetSdkVersion is now set to 28 and android-minSdkVersion is set to 19. ### Fix - fixed dark mode theme on iOS; - fixed an issue when the user wants to open a href:mailto link from the application; - fixed an issue with the CSWL 2019 Agenda when no link is associated to an event. 2019-10-02T13:18:54+00:00 TACOS v0.0.23 TACOS v0.0.23 2020-03-13T14:18:22+00:00 ## New - we have updated the videos section with new videos from (available in English and in French); - target API level is now set to 29 - Android 10.0 (minimum is 26 - Android 8.0). 2020-03-13T14:18:22+00:00 monarc-stats-service v0.1.9 monarc-stats-service v0.1.9 2020-07-08T12:01:28+00:00 First release. 2020-07-08T12:01:28+00:00 monarc-stats-service v0.1.10 monarc-stats-service v0.1.10 2020-07-16T06:57:02+00:00 Second release (with GitHub workflow to publish releases on pypi). 2020-07-16T06:57:02+00:00 monarc-stats-service v0.2.0 monarc-stats-service v0.2.0 2020-11-18T22:58:46+00:00 ## Version 0.2.0 (2020-11-18) ### New - First stable and, almost, feature complete version of Stats Service. A description of what has been implemented is available in the `docs` folder. 2020-11-18T22:58:46+00:00 monarc-stats-service v0.3.0 monarc-stats-service v0.3.0 2021-02-12T15:42:53+00:00 ### Notable changes - improvements to the existing processors (threat_average_on_date, vulnerability_average_on_date); - new processor for risks (risk_averages_on_date); - new command to purge stats older than the number of months specified in parameter; - improvements to the loading of the configuration; - improvements to the charts of the global stats page; - added new 'about more' page; - added new help page; - completed documentation; - various fixes. 2021-02-12T15:42:53+00:00 monarc-stats-service v0.4.0 monarc-stats-service v0.4.0 2021-05-11T14:38:53+00:00 ### Notable changes - redesigned the *Current Cybersecurity Landscape* dashboard; - added a *Cybersecurity Weather Map* page; - performances improvements for the processor ``threat_average_on_date``; - the lib/ helper is now using [PyMOSP]( in order to check if an object is present on MOSP (; - improved auto-update procedure. ![Screenshot_20210511_164933]( 2021-05-11T14:38:53+00:00 monarc-stats-service v0.5.0 monarc-stats-service v0.5.0 2022-06-20T12:27:47+00:00 - chg: [documentation] Updated documentation (9f38db11b382d8516fb71b60154aa0c7ba77004c); - chg: [API] CLIENT_REGISTRATION_OPEN is now set to True by default (b277436f81bbac1445822f0399dc348c5e283f70); - fix: [security] prevent the creation of new admin users (even by an admin) (257c16fed890bda8974594238a743f8afda0ff5a); - fix: replaced after_request by before_request for the API (88a276bf4d5f35e4e5da6ac065e1eb62f2892670); - small codebase fix for container image (82cdeaa714dbff14b9068c0b65c302ec4d02b3c4); - dockerfile and build pipeline (f8c663b61e1c8475d0f17060690d9920a1cc9e90); - updated Python dependencies. 2022-06-20T12:27:47+00:00 monarc-stats-service v0.5.1 monarc-stats-service v0.5.1 2022-06-21T21:59:16+00:00 Changes ~~~~~~~ - [dependenvies] Updated Python dependencies. 2022-06-21T21:59:16+00:00 monarc-stats-service v0.5.2 monarc-stats-service v0.5.2 2022-07-04T08:41:37+00:00 ## Changes - [API] patch on client now expects again a model from Namespace (client_ns). - Updated Python dependencies. - [documentation] Updated links to documentation. - [documentation] Updated information about installation. - [deployment] added docker-compose.yml file. ## Fix - [API] enable patch method for enabling/disabling stats sharing. 2022-07-04T08:41:37+00:00 PyMOSP v0.3.0 PyMOSP v0.3.0 2021-03-26T15:06:02+00:00 * PyMOSP is now using the API v2 of MOSP; ' simple tests are included. 2021-03-26T15:06:02+00:00 PyMOSP v0.4.0 PyMOSP v0.4.0 2021-03-30T22:22:36+00:00 New ~~~ - [command line] It is now possible to use PyMOSP as a command line tool. Only for listing objects for the moment. [Cédric Bonhomme] - [objects] Added creation of objects and some tests. [Cédric Bonhomme] - [tests] added files for the future tests on JSON schemas. [Cédric Bonhomme] Changes ~~~~~~~ - [release] Bumped version number. [Cédric Bonhomme] - [tests] Lint with Flake8. [Cédric Bonhomme] - [tests] added test on get objects with uuid and language. [Cédric Bonhomme] - Updated .gitgignore to ignore .python-version file. [Cédric Bonhomme] Fix ~~~ - Typo. [Cédric Bonhomme] - [documentation] Fixed example file. [Cédric Bonhomme] - [type] Fixed type of result of objects() and add_objects() function. [Cédric Bonhomme] Other ~~~~~ - Updated chagenlog. [Cédric Bonhomme] - Updated chagenlog. [Cédric Bonhomme] - Updated README and pyproject.toml. [Cédric Bonhomme] - Fixed bad format of link in README. [Cédric Bonhomme] - Replaced str by map when joining Python version number. [Cédric Bonhomme] - Removed useless file. [Cédric Bonhomme] 2021-03-30T22:22:36+00:00 PyMOSP v0.4.1 PyMOSP v0.4.1 2021-03-30T22:23:00+00:00 Fix ~~~ - [documentation] fix the documentation in the README. #HowToFuckUpARelease. [Cédric Bonhomme] Other ~~~~~ - Updated README. [Cédric Bonhomme] 2021-03-30T22:23:00+00:00 PyMOSP v0.4.2 PyMOSP v0.4.2 2021-03-31T13:42:10+00:00 Changes ~~~~~~~ - [core] Python requirement set to >=3.8,<4.0. [Cédric Bonhomme] 2021-03-31T13:42:10+00:00 PyMOSP v0.4.3 PyMOSP v0.4.3 2022-01-12T11:21:48+00:00 ## Changes - [dependencies] Updated request and mypy. [Cédric Bonhomme] - Cosmethic changes. [Cédric Bonhomme] - Fixed conflict in file. [Cédric Bonhomme] - Minor changes in README file. [Cédric Bonhomme] ## Fix - [tests] fixed key name of the result. [Cédric Bonhomme] - Removed useless import and fixed duplicate value in [Cédric Bonhomme] ## Other - Merge branch 'master' of [Cédric Bonhomme] - PEP 561 -- Distributing and Packaging Type Information. [Cédric Bonhomme] 2022-01-12T11:21:48+00:00 PyMOSP v0.5.0 PyMOSP v0.5.0 2022-01-20T14:07:20+00:00 ### New - [object] it is now possible to delete an object from a MOSP instance with the API. [Cédric Bonhomme] ### Changes - [dependencies] Updated Python dependencies. [Cédric Bonhomme] - [tests] rename a test name. [Cédric Bonhomme] - Get MOSP instance URL from environment variable. [Cédric Bonhomme] - [workflow] Updated GitHub workflow. [Cédric Bonhomme] - [tests] enable test_create_object. [Cédric Bonhomme] - [tests] tests are now using the test instance of MOSP. [Cédric Bonhomme] ### Fix - [typing] delete_object returns the id of the deleted object. [Cédric Bonhomme] - Fixed an issue when creating new objects. [Cédric Bonhomme] - [workflow] Updated GitHub workflow. [Cédric Bonhomme] 2022-01-20T14:07:20+00:00 Diagnostic 1.0 Diagnostic 1.0 2017-11-17T14:41:48+00:00 This is the first version of the CASES Diagnostic. The application should be found by typing the address in your navigation bar. Do not forget to add the Host-Only card to make the VM Work, as it is explained in the [Quick Start Guide]( >Credentials for this VM (under the format `Login`:`Password` : >Login Diagnostic : ``:`Diagnostic1!` >SSH login: `diagnostic`:`diagnostic` >Mysql root login: `root`:`4da74c250b218c70989d982fb7e5486b00ef79cedfd5e4847ac7a8ff4ff8aba5` >Mysql diagnostic login: `diagnostic`:`f5e75d203bfac8965aab080f121151db92b0d529acffb0097dda1013f3611ade` >SHA512 sum : `e0649312e8e217a092bd6e2e7a0fac2d46d4506c619f807d2e6d5594101c223602e50949986149ef6b4ac27bfdf531cc2f1e13952d0d9a34dab68d2d4081ea80` > SHA1 sum : `381680be239ab821f594fa55ca29e2b6dbc21644` 2017-11-17T14:41:48+00:00 Diagnostic 1.1 Diagnostic 1.1 2018-06-11T09:57:28+00:00 What's new in this new version ? >**CHANGE LOG VERSION 1.1 JUNE 2018** > >- Update Ubuntu from 17.04 to 18.04. >- Update Php from 7.0 to 7.1. >- Add color to the category in the report (radar chart and tabs). >- Update the Diagnostic's logo from CASES to DIAGNOSTIC. >- Modify report to be more visual. >- Update calculation method (no more Planned Maturity, there is now a Non Applicable button). >- Display red points instead of triangles in the diagnostic to match with the MONARC convention. >- Use of OpenSSL to export and upload new diagnosis which wasn't working anymore since Php7.1. >- Add category tab in the adminitration mode. It is now possible to add/modify/delete new categories for the >Diagnostic. >- Update the administration mode. It is now possible to translate questions and categories without getting in >the .po files. >- Update documentation to match with new features. The application should be found by typing the address in your navigation bar. Do not forget to add the Host-Only card to make the VM Work, as it is explained in the [Quick Start Guide]( >**Credentials for this VM (under the format** _`Login`_:_`Password`_**) :** >Login Diagnostic : _``_:_`Diagnostic1!`_ >SSH login: _`diagnostic`_:_`diagnostic`_ >Mysql root login: _`root`_:_`9091d0a91ade1803fb5b4dce`_ >Mysql diagnostic login: _`diagnostic`_:_`0376dea30f32943d3cd6c48b`_ >SHA512 sum : _`b3906022eaf981168e0bf05811e8311e396056733d32b752bacb861d15fe7756426cada7c3a468e3e8f2766a6689e905280b4bbf0335972e03ea4323fa1c0e59`_ > SHA1 sum : _`dfda33de19120793f31ccc30b2ee14d1292ced86`_ 2018-06-11T09:57:28+00:00 Diagnostic 1.2 Diagnostic 1.2 2018-11-14T09:54:42+00:00 What's new in this new version ? >**CHANGE LOG VERSION 1.2 NOVEMBER 2018** > >- Add language tab in the administration mode. It is now possible to add/modify/delete new languages and new translations. >- Add confirmation before deleting something(questions, categories, languages, translations). >- Add Reports tab in the administration mode in which we can download/upload report template modals. >- Add Settings tab in the administration mode in which we can change some global settings and add diagnostic statistics. >- Add importation/exportation for questions, categories and translations. >- Add an Uid for the Diagnostic, for the questions and for the categories. >- Add statistics importation for a diagnosis. >- Add several information in a diagnosis. We can now choose the activity of the company and its number of employees. >- Change the threshold calcul method for each question. It is now equal to threat*weight depends on the question. >- Add blocking question. Used if an essential domain for the entity is not managed. >- Update the evolution of maturity bar chart. We can now see the average of diagnoses of the current domain and overall diagnoses done for a year given. >- Add an help part for the organization and synthesis parts in a diagnosis. >- Aesthetics and ergonomics improved in the report. Better colors, N/A displayed instead of 0% out of 0%. >- Translation files now divided between questions, categories and translations for more visibility. >- Update documentation to match with new features. Do **not** forget to add the Host-Only card to make the VM Work, as it is explained in the [Quick Start Guide]( The application should be found by typing the address in your navigation bar. >**Credentials for this VM (under the format** _`Login`_:_`Password`_**) :** >Login Diagnostic : _``_:_`Diagnostic1!`_ >SSH login: _`diagnostic`_:_`diagnostic`_ >Mysql root login: _`root`_:_`4ff519383e1ba8cc948395b8`_ >Mysql diagnostic login: _`diagnostic`_:_`4a76bf589340dd3ce86168a0`_ >SHA512 sum : _`d8be0abaff0fac0cfbec18ef80334a83c7a7870d71db04afb6a1356492e45114adfe3035779bb462fa048b5d7f380d6cbb133aeec1d285e65cb55671b0d4e6fa`_ > SHA1 sum : _`8e1e776634c75c226607e6f7ca04db785c113b6f`_ 2018-11-14T09:54:42+00:00 Diagnostic 0.1 Diagnostic 0.1 2019-04-25T08:15:32+00:00 This is the inital release of sensor-d4-tls-fingerprinting. # Current Features * Extract x509 certificates from pcap files or network interfaces * Export TLS sessions description in JSON form - to stdout or to disk * Export Certificates to disk * Fingerprints TLS client/server interactions with ja3/ja3s * Fingerprints TLS interactions with TLSH fuzzy hashing on the tuple {ja3, ja3s, [certficate.issuer, certificate.subject]} # SHA 256 # ```shell 2c52f40ce7b606b4edeef7d9c6b2b5f622464effcfd3408852019b567e0620df d4-tlsf-amd64l ``` 2019-04-25T08:15:32+00:00 MOSP v0.1.0 MOSP v0.1.0 2018-05-13T15:09:11+00:00 - first beta release of MOSP; - basic features are implemented: management of JSON objects, management of JSON schemas, management of users and organizations; - it is possible to edit a JSON object with a JSON editor which is generated thanks to the JSON schemas; - a basic API let the user interact programmatically with the JSON objects. 2018-05-13T15:09:11+00:00 MOSP v0.2.0 MOSP v0.2.0 2018-05-30T05:36:34+00:00 - the JSONB PostgreSQL type is now used instead of the JSON type; - the JSON editor has been upgraded and is now properly working with Bootstrap 4.1; - the interface to edit JSON data has been revamped and is a lot cleaner; - DataTables is now used for all tables; - a new interface displays all the JSON schemas in the organization(s) of a user; - a panel to manage users of the platform has been added; - the Web interface is internationalized in French (80% of strings are actually translated); - various UI improvements. 2018-05-30T05:36:34+00:00 MOSP v0.3.0 MOSP v0.3.0 2018-06-01T09:28:59+00:00 - new Web interface to list, create and edit JSON schemas; - improved management of users. It is now possible to block a user; - translations improvements; - various UI improvements. 2018-06-01T09:28:59+00:00 MOSP v0.4 MOSP v0.4 2018-10-05T07:21:14+00:00 - it is now possible to select one or several licenses for an object (#2). A script is provided in order to initialize the database with licenses from; - the values of a JSON object can now be exported to a CSV file; - the management of permissions has been improved; - added a new profile page for users; - various fixes and UI improvements. 2018-10-05T07:21:14+00:00 MOSP v0.5 MOSP v0.5 2019-02-23T23:54:39+00:00 - major improvements to the API. It is now possible to create a valid JSON object programmatically with the HTTP POST method. The validity of the submitted object is checked against the specified JSON schema; - the project has now an official logo (#7); - a human.txt file has been added ( - various fixes and UI improvements. All views have been improved; - a documentation is now available and will be improved ( 2019-02-23T23:54:39+00:00 MOSP v0.6 MOSP v0.6 2019-03-11T23:04:28+00:00 - added the possibility to link objects (#8); - the footprint (SHA 256 sum of objects is now displayed); - added the possibility to copy an object to the clipboard; - added a terms page; - improved the organization page; - improved the admin/users page; - minor UI fixes. 2019-03-11T23:04:28+00:00 MOSP v0.7 MOSP v0.7 2019-09-12T12:05:05+00:00 - it is now possible to specify linkgs between objects when creating a new one; - it is now possible to acces to an object with its id or with the UUID of the JSONB object attribute of this object (<UUID>); - it is now possible to copy an object from one organization to an other (#11); - it is now possible to download all JSON objects validated by a schema. Objects are returned in a flattened list; - the contact e-mail address from the terms page is now using the one defined in the configuration file; - updated version of json-editor used in the project. 2019-09-12T12:05:05+00:00 MOSP v0.8 MOSP v0.8 2019-11-28T19:57:27+00:00 - Add a warning when the UUID of new a object is already taken (#14); - Generation of MISP galaxies and clusters based on an object from MOSP (#15); - Add a button in order to help the user generate a UUID easily (#16); - Added a way to list the recently created/updated objects for an administrator; - Added shortcuts to create new users and organizations. Simplify the creation of new users/organizations; - The footprint of objects is no more displayed; - Improved the performances on JsonObject GET many by removing useless attributes from the result; - updated Bootstrap to the version 4.4. 2019-11-28T19:57:27+00:00 MOSP v0.9 MOSP v0.9 2019-12-12T20:15:54+00:00 ## 0.9 (2019-12-12) - major improvements to the structure of the backend and to the models; - introduction of tests with pytest; - now using GitHub test workflow (GitHub Actions); - added app.json file for easy deployment with the Heroku button. 2019-12-12T20:15:54+00:00 MOSP v0.10 MOSP v0.10 2019-12-19T12:02:22+00:00 - added token based authentication for the API. Documentation is available: - the project is now using poetry. ![Screenshot_20191219_130744]( 2019-12-19T12:02:22+00:00 MOSP v0.11 MOSP v0.11 2020-02-03T14:41:17+00:00 - fixed an issue related to the authentication via the API (which is used by the JSON editor); - improvements to the authentication service. 2020-02-03T14:41:17+00:00 MOSP v0.12 MOSP v0.12 2020-04-09T07:05:20+00:00 ### News - added email attribute for users; - added password recovery feature ([#13](; - added a view which returns the definition of a schema (text/plain). This is used for external references in JSON schemas. ### Improvements - improved generation of MISP clusters from an object: all values (properties) not directly useful for the context of the current schema in MONARC are assigned to the key 'meta'; - migrate form Flask-Script to the built-in integration of the click command line interface of Flask; - updated JSON-editor for the JSON objects and added a new simple editor for the JSON schemas; - various minor improvements and bug fixes. 2020-04-09T07:05:20+00:00 MOSP v0.13 MOSP v0.13 2020-04-23T11:47:32+00:00 ### News - added new API which is returning data about relations between JSON schemas hosted on the platform. These data are generated with the networkx Python library and returned as JSON object compatible with D3.js; - added a new D3.js graph which is using the new API; - added a new view which presents all relations (refs) of a JSON object (self, external and recursive references are supported). ### Improvements - various minor improvements and bug fixes. 2020-04-23T11:47:32+00:00 MOSP v0.14.0 MOSP v0.14.0 2021-06-17T19:42:41+00:00 ## Notables changes ### News - [core] Added self-registration for the users with email confirmation; - [api v2] Added new API (OpenAPI Specification); - [views] Generation of an Atom feed of the schemas recently published and updated on MOSP; - [views] Generation of an Atom feed of the objects recently published and updated on MOSP; - [organizations] A user can now join an organization which has no membership restriction and as well leave an organization. ### Improvements Many improvements to the user interface. See the [CHANGELOG]( for the details. 2021-06-17T19:42:41+00:00 MOSP v0.15.0 MOSP v0.15.0 2021-07-29T08:31:26+00:00 This release introduce the versioning of objects: #35 See the changelog for more details. ![diff]( ![list_versions]( 2021-07-29T08:31:26+00:00 MOSP v0.16.0 MOSP v0.16.0 2021-09-15T09:05:12+00:00 This release introduces the locking of objects: #40 See the changelog for more details. ![Screenshot_20210915_110414]( 2021-09-15T09:05:12+00:00 MOSP v0.17.0 MOSP v0.17.0 2021-09-30T12:32:57+00:00 This release introduces the management of collection of objects ( See the changelog for more details. ![Screenshot_20210930_145437]( 2021-09-30T12:32:57+00:00 MOSP v0.17.1 MOSP v0.17.1 2021-10-28T11:13:40+00:00 ## What's Changed - Translated using Weblate (French) in and many more new languages. - Added type check with mypy. - [templates] added functionality to share a collection on social websites via the btn-group menu. **Full Changelog**: 2021-10-28T11:13:40+00:00 MONARC v2.0.0 MONARC v2.0.0 2017-08-07T09:05:52+00:00 * initial stable release of the version 2 of MONARC. 2017-08-07T09:05:52+00:00 MONARC v2.0.1 MONARC v2.0.1 2017-08-28T07:38:55+00:00 ## Enhancement - Auto-complete function in the creation of a specific risk (#29) - Remove the category for operational risk (#26) - update of the database - the database of MONARC is now backed up before an upgrade ## Fix - Import bug : Format of duedate in recomandation (#30) - Problem when a label of an impact contains a character such as '&' or '%' (#24) - Lost operational risks of assets in library after a snapshot (#25) - Problem setting a comment in new scale row (#24) - hash of users' passwords were exposed through the API as reported by Thomas LARCHER, Cyber Security Team of PwC Luxembourg. > Login and passwords for the MONARC VirtualBox image > - MONARC application: admin@admin.test:admin > - SSH login: monarc:password > - Mysql root login: root:6a2ae9a3c5ddabeb933c113d8be5bfe8f7b946bb3f7cb41d0464d3855c6451fb > - Mysql MONARC login: sqlmonarcuser:bf5ee4c5e26d8c65170db90783762c8d7cf2bb511fc732d1c0ce3ce68206ce47 > > sha512sum: a11b29c1c0b3272f6b78791b83d8d4e36633fe451f6cb92381cb646c0ad5b397777e2ece66a55ad993352a2a4124acf69f1e13c59f55b5eedff5c779fa36a0a1 > sha1sum: 1edcde1cb4d421fc20b9e424673debea6b2ef7bc 2017-08-28T07:38:55+00:00 MONARC v2.0.2 MONARC v2.0.2 2017-10-10T12:24:11+00:00 ### New - MONARC is now available in Dutch. ### Enhancement - updated German translations. - updated the font used for the images in the generated reports. - minor improvements in the configuration. ### Fix - Lost operational risk when importing from MONARC Common DB (#32) - PHP Notice: Use of undefined constant i (#33) > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:d6d172fa08861a8b255866ef95b788131fae560478ccbe2191db03db30811be2 > * Mysql MONARC login: sqlmonarcuser:6794a65aedb37b5eeee44ff991c1808b3cd5d1ee39889e35cefe4f5f20a19919 > > sha512sum: a2113c67eb934773a08c3761204a2b867d97a1dd2c5ef2550025c119c4deb5dfda6501a759b0e5e2becbc5810497ba87d230369bbbb7042f92ebced0a3ba7a4a > sha1sum: 6ffed042ba8d61b8d79406d547c6378e8d405228 2017-10-10T12:24:11+00:00 MONARC v2.0.3 MONARC v2.0.3 2017-10-13T06:16:34+00:00 - set default deliveries in english. - Set NewCenturySchlbk-Roman Imagick font. > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:b2d87a848f9e08357ee9a31c4b633e338fa6cbf1e2f7ca7268857312473d2ccf > * Mysql MONARC login: sqlmonarcuser:f6ef010f82cfaa0f6ca8d9b4b508b53de4e534b1a7e42cda77616c62ee7652dd > > sha512sum: 9c53fc6a15e7af83fa323bee69f09d49401065726b33b172359095f11f3c2d72c5b908cc5925bae9bbbcb2610ee52cbd62d84386db305df2f7c92d3456e5ebae > sha1sum: 3fe8bdd164040f1b63591fedbd89d865c91767dd 2017-10-13T06:16:34+00:00 MONARC v2.0.4 MONARC v2.0.4 2017-10-27T13:00:33+00:00 - fix a bug with salted passwords that prevented users to update their password. Users may have to use the password recovery functionality (zm-core). Reported by Nicolas SCHWARTZ, Cyber Security Team of PwC Luxembourg. - set default deliveries in english (zm-client); - block the probability in the threat assessment in 1.2 of the method (ng-anr). > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:057bdb05f15aa99f5ccaeaacfcbb2b333c5fa64a8c1a4f8fbaa94f5dcba4aa61 > * Mysql MONARC login: sqlmonarcuser:78efe699176030b05d960d941ab1df88d592dc59fed2dbb2138ea5a1160b790f > > sha512sum: 80e53be785d355d4f635bed34e4e59d2c0aa676114ac3b3d4a34df6b9b3e9081675a5ab764a879b49c75e7faf265fa544ba6c364c4123c3e7b784d5bcc1109cd > sha1sum: 7631700b8e322d05e2af73b51bbfb2ed05733c65 2017-10-27T13:00:33+00:00 MONARC v2.1.0 MONARC v2.1.0 2017-12-04T06:51:22+00:00 ### Enhancement - cleaning of the initial database structure. - split database model and data. - simplify the panel to create new MONARC clients. - improved the table of MONARC clients of the administration panel. - removed all useless column of the 'clients' table. - removed cities and countries tables in the database. - added a condition to hide/show probability field on Threats assessment. - it is now possible to export a whole analysis (or an asset) in JSON or as an encrypted JSON file. Analysis exported with the legacy system can still be imported in MONARC. - it is now mandatory to specify a level of permissions when creating a new user. ### Fix - minor fixes in the forms of the user profile page. - minor translations fixes. - fixed a bug that prevented users to update password without the password recovery feature. > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:b5cf730344315f6ab5538701f20b444cfdce12462c767602d5a6a20d07e71160 > * Mysql MONARC login: sqlmonarcuser:f89220295d4c4d7ebef4097555102f62215149cb35eaff5f383b4796f5df421e > > sha512sum: 59fb95ab0e76e474b34ccc273a5478c79f8a586cb35597e046067019971de5ad90b56c794f28b2cbc104c0b3af5143c46c2b3c3dfe7f52ea1dd4fe997841e350 > sha1sum: 46206c2366a8f8fb7a0c0854b4d8f0306bbf29f7 2017-12-04T06:51:22+00:00 MONARC v2.2.0 MONARC v2.2.0 2018-02-01T09:15:02+00:00 ### New - generate deliverable on 4th step of method (#51) - export all of risk analysis data (#28) ### Enhancement - option of export tables in a csv file (#52) - show version MONARC on left panel (#50) - ensures new users (of the back office) are created with a level of permissions (#48) - the back office displays the appropriate view based on the user permissions (#48) - set the selected attribute for the search filter of models in the back office ### Fix - user operational risk - tag (#55) - operational risk - tag (#54) - detach a tag from an asset (#53) - operational risk importation (#64) - various minor fixes in the back office (management of models) To update, check out our [update]( instructions. This release includes a consequent changes in the database of the back office and in the synchronization process of the deliveries templates (between the back office and the different clients instances). If you are using a back office, be careful to also update your ansible playbook ([instructions]( > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:baa1bf66ec891f9e6dbf6dbe281f530c46da2158fe66091ac6b62eaeebb9054d > * Mysql MONARC login: sqlmonarcuser:5eef25f5440470a202e0dfe46fb1360c9ae71bec3997f06cdeabc21b222a6a1d > > sha512sum: 458564d616d4711f119c1593f8929e4db0afa665c6141ed142954079663afb2f1ffbf97d4c73069903778d60f986e86db26acf6462ac8afaebc3f62c6a7edff7 > sha1sum: beebc22d4fab4181716895dd574ba2dd70ba08bd 2018-02-01T09:15:02+00:00 MONARC v2.2.1 MONARC v2.2.1 2018-02-14T13:40:54+00:00 ### Enhancement - Lack of information in the final deliverable (#65) - Update template of third deliveries ### Fix - CID/CIA translation in generateImpactsAppreciation for the deliveries (monarc-project/zm-client#3) - Removed useless dependencies to City entity. > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:30721818387165578a99ac1d5ec1395f114f0d8c7f9bbcdd8d3c3058b1276a88 > * Mysql MONARC login: sqlmonarcuser:3b64d5327a384d2e426d8265e68bc4e820f5f38b7a304663ff05da045eabf492 > > sha512sum: 3779f90aed47fe3f2a2f09dbd1efeee6c9033533092075cce1b8648149e091a587dbc210a8f60758aa0c39cab4b753e9c386f64ffe0dc62f9d3ccc6e33933b98 > sha1sum: 194d18b2b6f4eae8d2f4248a35e117301fe81a36 2018-02-14T13:40:54+00:00 MONARC v2.3.0 MONARC v2.3.0 2018-04-27T13:30:33+00:00 ### New - an administrator of a MONARC front office instance is now able to set custom templates for deliveries per step. ### Enhancement - default deliveries templates were improved; - the section dedicated to the management of the organization has been moved in a dedicated view; - improved the switching between the different available languages; - improved the generation of the deliveries. ### Fix - fixed a bug in the generation of the deliveries (#84); - Inconsistency of Threat and Vulnerability Tables (#82); - various minor fixes. > Login and passwords for the MONARC VirtualBox image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:0906383d4a1355519b5ec17b917dddd673d4dd94fe367d1b964723e1775373a2 > * Mysql MONARC login: sqlmonarcuser:8a9fa55c698290788a2c141326b778e1dbc358b05719e3e6a603216701ca4d14 > > sha512sum: c8e2a25532d53dd8e3357491f50432f01f94851b26a0449d7130bfcd4e574ea12cec6c9acfc99bc4c5ad39b2ffa04354affa90c76a86af903089787823bfefb1 > sha1sum: e155dccb43200921d346ddd1e31d08c725b96401 2018-04-27T13:30:33+00:00 MONARC v2.4.0 MONARC v2.4.0 2018-05-14T09:37:48+00:00 ### New - the dashboard of MONARC has been entirely revamped and is now using D3.js. ### Fix - restart from an existing analysis (#87). 2018-05-14T09:37:48+00:00 MONARC v2.4.1 MONARC v2.4.1 2018-05-30T09:13:50+00:00 ### Enhancement - the dashboard has been improved with more interactive graphs; - the dashboard view is now part of the analysis. The home page of MONARC simply lists the projects. ### Fix - Removal of a recommendation on same risk of different asset of the same type (#92); - Order of operational risks (#88). > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:b62f94dc62eddedc62e146d809f92d3a70899fa7371552338e9069e6037b2ee2 > * Mysql MONARC login: sqlmonarcuser:92b5bddaeebb32d235e3add6ff9622bec23ce8ea2be97451d0021e0fa34aec5d > > sha512sum: 864c565b7cfdf9b9ee248407ab3fb9df26cdb3c738cd3fc0765643cd535af7ca73d204c69d7ce61acd7cec5a6a17b58bfc3f9b1a7ca70ee1815e6e736e589dee > sha1sum: ac5c39e61b6e9faa91dca99de8e5f3b7298ee74a 2018-05-30T09:13:50+00:00 MONARC v2.4.2 MONARC v2.4.2 2018-06-08T12:45:20+00:00 ### Enhancement - improvements for the breadcrumb used in the graphs of the dashboard. Moreover it is now possible to click in the items of the breadcrumb in order to navigate between the different graph's levels; - the deadlines of recommendations are now set with a date picker in the fourth step (#98); - Removed the filter on the checkbox of the step 3 to display the dashboard of residual risk (#99); - the column 'phone' has been removed from the 'users' table and in the models. The application must store the minimum amount of information required on users; - Validate recommendations for operational risks (#102); - the translations have been improved. ### Fix - Operational risks are not updated (#93); - In the 4th deliverable, an inherited risk is displayed at -1 and in red color (#100); - Fixed a problem with some translations in the legends of the report's graphs; - Removal of a recommendation on same risk of different assets of the same type (#92). > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:d9f7bdbc867c896fc0cb4f99dd24c53fa773471e2d6769de21454f40202b84cc > * Mysql MONARC login: sqlmonarcuser:dfb4f4daf219a8d0427f37f7ed1ea631215f89db8664f024781d78f81e3b836a > > sha512sum: 5bb563316964e611d99dac633bed1d980711203008b45dfe8af98b572bbf506fadc0384d673b02d1fc0879aa51587d0e5712e4f1e46ab325ecd26f809c75df26 > sha1sum: 44c6a1efd2ca0e8386dd649f6db9b9a2a2d1147e 2018-06-08T12:45:20+00:00 MONARC v2.5.0 MONARC v2.5.0 2018-07-04T06:41:40+00:00 ### New - all dashboard data can now be exported to a CSV file with tabs; - fine grained export of risk analysis (choice between method steps, interviews, existing controls and recommendations); - it is now possible to create a new recommendation from an existing one; - account deletion / right to erasure (#109). ### Enhancement - how to erase the evaluation of all threats of a risk analysis (#97); - the risk treatment view has been improved (#96); - MONARC and the back office are now using AngularJS 1.7.0. ### Fix - impossible to edit some fields in BO. Only is possible in the default language of instance (#108); - md-datepicker sends the day before the one that was selected (#105); - the filter by tag is not working on Knowledge base > Operational Risk (#103); - the generation of deliverables has been improved (bullet point lists) (#101); - various minor improvements and fixes in the back office of MONARC. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:a9d19611b64f2601745cd589bea57cb3f683e1710eaed3f1c02359194d607063 > * Mysql MONARC login: sqlmonarcuser:0fdca696bd7dcab9f79b3c038922ed05d91164fb6c1eb17e5b2d78e987ff685f > > sha512sum: 4fa4bbd4cb7bf3ccb82ec28095eb639f8f813fa1ead83acb085639e0706353992c5775345fa803930a65d3b9b3037e0b38328bbdf83728f6a701ae649f6b9c69 > sha1sum: 7fdc16c8e62b09527583389b4ba7775c94b7d6ac 2018-07-04T06:41:40+00:00 MONARC v2.6.0 MONARC v2.6.0 2018-07-20T12:48:14+00:00 ### New - MONARC users who open the home page in the web interface will see an image in the bottom left corner with the text "up-to-date" in green, "update available" in orange or "security update available" in red. This will make outdated version more visible for users of MONARC. This version checking is performed thanks to a [dedicated service]( ### Enhancement - the import and export functions have been improved; - creation of recommendation and missing field (#115); - make an easy link to implement the recommendation directly from the risk view (#112). ### Fix - fixed a bug in the table Risk treatment plan management. - problem on date parsing with the date-picker with non-US browsers (when using date.toLocaleString) (#117) - it is not possible to reset the ``duedate`` attribute of a recommendation since the introduction of the date-picker (#116) - review and correct the functionality of import by fusion or merge (#62) - minor translations fixes. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:bdd13ca944f684b69333d240b95db1ccf404a42f50e0bc9a371ee8033d676f47 > * Mysql MONARC login: sqlmonarcuser:1b1f9eab332cd9ec3e06c9bbf7b927e29087bd10277bb38321bf6a7448b07e16 > > sha512sum: 3512fa9f1fa55876ac915e1720d777688e0f5f8307a48ae7ed5b32d9ae229b0734980007987090f7c9eef007b949db7aa452131fb6705264686cdc4d31e06691 > sha1sum: c93dc81225db935de7efdbb4d5c9b3ca55721eed 2018-07-20T12:48:14+00:00 MONARC v2.7.0 MONARC v2.7.0 2018-08-22T13:15:02+00:00 ### New - this release introduces the statement of applicability (SOA) module for your risk analysis. This is a first step towards the awaited [Statement of Applicability & Gap Analysis module]( ### Fix - Error in translation in sector 3 of Final report ([#124](; - The management of the position in the library is not working ([#123](; - Empty categories in the library ([#122](; - Impossible to order the questions in the back oficce ([#121](; - Hidden impacts function doesn't works ([#119](; - Search and sort filter for import ([#38]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:5ef15b9c19b673cac668cf0e3ef91fd51e6c38ffe8dbb52d0b1865f3545bd6c5 > * Mysql MONARC login: sqlmonarcuser:662fb82de2ab005af76257664bdd2410549aa7398165c6827a3911843aaa2cc2 > > sha512sum: 2ee45c6dc9098123251be08acb9841bd429cfe4081df2dd6e2834a307821b4f2b94cce13d53ebae4619f087bc536c543d6315cc2d3a071ebc1d3ecd3c93545fb > sha1sum: 69a35973edeb1d81707caf1e3a984fc1b84c510d 2018-08-22T13:15:02+00:00 MONARC v2.7.1 MONARC v2.7.1 2018-09-07T11:58:47+00:00 ### Enhancement - inform user which rights he has on each risk analysis (#131); - display read/write access of the currently connected user on the home page (list of analysis) (#130); - improvements to the statement of applicability (SOA) module (speed improvements); - minor improvements to the home page. ### Fix - impossible to download a report when user has no wright access (#133); - name of columns of the evaluation scales are not displayed when a user has not write access (#132); - problem with UTF-8 characters in CSV export files. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:dcb4fbeabd9c856ac8cfdb90075866bd9b58b65f50b1580c6ecf6ae633c33cfb > * Mysql MONARC login: sqlmonarcuser:3f2e1e05c55f5878e17d0d03bf22bfeccf59388d51ee2aa3f65f1dd7bcbabd56 > > sha512sum: c7767ff30e965b9feb7c34ae6a57439196ac10e0b897ca3bef2b7c4428709f08912a751692183fe1f65f486728b410e221b402c15b18e383d01b56a936b5b3af > sha1sum: cd5713c924eed6f85956432a44401d9fced816d4 2018-09-07T11:58:47+00:00 MONARC v2.7.2 MONARC v2.7.2 2018-10-08T13:43:07+00:00 - MONARC is now compatible with PHP 7.2 (#89). Future MONARC virtual machines will be based on Ubuntu Bionic LTS; - Reports not generated in user's language or selected templates (#129); - All your rights have been revoked. Please contact the manager for your organization (#110); - various improvements and minor fixes in the back end. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:e704ff96b594ce8a0febee5d80911a7cdfa87f9e945c61f105674b868aa28a88 > * Mysql MONARC login: sqlmonarcuser:df51ab4f1e64bb7f26a6a669467a98cbbef4ecd024c0670fb61cad8cf20326e5 > > sha512sum: 35caf7f4f4cb3e50ca213d7e8032a5f1085ce397bd22c4967a469b20306b0c5e80b51e24842ae64a290f17d4524bde2db8239f3d9b6384aebbf2fe5d55667d27 > sha1sum: f013ac02be1e4269ca9a75f9bfcdd2e053a30bd1 2018-10-08T13:43:07+00:00 MONARC v2.7.3 MONARC v2.7.3 2018-10-25T12:37:14+00:00 ### Enhancement - added backend capability for the bulk creation of objects; - various improvements and harmonization of the backend code; ### Fix - Sort order for operational risks in final deliverable annex D (#111); - Upload of template deliverable fails in Dutch (#141); - SOA is now included in snapshots. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:c58bdd1a57042736a22697772658c63d030e62d3ce1e15f4db6e8346f9ad2191 > * Mysql MONARC login: sqlmonarcuser:f11ab8d12ca1cc75f37749f9d4443c5d2d5ed3400ba3671b68b14c52c38d667e > > sha512sum: 90ef2bea5f8a0171c8ff01fb6031cbe4ae22469400533566be55c3c224558f90202de64b9cdbe35771a5fa256cab19ff2ab280eaaf65c3686577066f25a4e9c0 > sha1sum: 45e041629b24bc73980e1640d91cf4b71c887967 2018-10-25T12:37:14+00:00 MONARC v2.7.4 MONARC v2.7.4 2018-11-27T14:10:52+00:00 ### Fix - Fixed risk target calculation [199db6c](; - Fixed a typo in SoaCategorySuperClass [ea72881](; - Fixed an issue when operational raw risks are hidden before an import [f382c91](; - Fixed some minor issues in the views [cbbd94e](; - Fixed several bugs in the reports generation (in the PHPWord library) caused by special characters. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:cae29e7bcb34bd7c2f7306580ea3ed65e1b8a9bc6b1e59279b7fd9cc909531cd > * Mysql MONARC login: sqlmonarcuser:e52bd3b34c3733b67031842a8b0490fcfecccd86f8567fb2ece84feaea8fbeda > > sha512sum: 99efefe824f3b413b53e31c797176d0dffcc65f8e2d370c52f8314ca83f38ebcede32248f08243b868eda14cc8882724b63d0eee83cd8481c28d92f963066207 > sha1sum: 4b4f401a8be15c4c8d244cc4f6a467c386f01a75 2018-11-27T14:10:52+00:00 MONARC v2.8.0 MONARC v2.8.0 2019-03-01T00:46:30+00:00 ### New - [management of multiple security referentials](; - [mapping between security referentials](; - [improvements to the statement of applicability](; - [batch import of objects](; - [new chart for the dashboard](; - [MONARC Objects Sharing Platform](; - it is now possible to set a page for your terms of service when MONARC is used to provide a service. ### Fix - Fixed an issue when deleting threat theme [#143]( - Improved the go back on risk sheet [#95]( 2019-03-01T00:46:30+00:00 MONARC v2.8.1 MONARC v2.8.1 2019-04-24T09:56:30+00:00 ### New - the dashboard can now be exported to a CSV file or to a presentation file (.pptx). ### Enhancement - Improve the treatment of a risk ([#114](; - Improve risk sheet screen ([#139](; - the cartography in the dashboard has been improved. ### Fix - Loss of recommendation link ([#150]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:d39bdf1c3eb4cbaf58247ef790bc47cb332b40787458f4f29a7d8291097db011 > * Mysql MONARC login: sqlmonarcuser:553645f77778c7924a7a4fca6f232e525c502a86338e7699a737be6e007930e3 > > sha512sum: 35413b10005293bcae69d2bfb8e78a9eec51c0948e809987ab724b6d0830365eab058405104ea9b7171aafca3d375338f230e74350b041f3be02e358ecdc43fe > sha1sum: 6c55e415de1d8af38d84d3bc55ea04a3906d673e 2019-04-24T09:56:30+00:00 MONARC v2.8.2 MONARC v2.8.2 2019-05-28T06:37:18+00:00 ## New - the MONARC core objects (assets, threats, vulnerabilities and risks) are now identified with UUIDs. We published the objects on the [MONARC objects sharing platform]( Risks from the CASES models are also [available](; - Assets, threats, vulnerabilities, risks and referentials can be imported in the knowledge base of your analysis from MOSP without leaving the MONARC user interface. ## Enhancement - Adding referential afterwards does not update the knowledge base [#156]( ## Fix - Import analysis in 2.81, exported from 2.72, gives errors [#152](; - Edit label of added Referentials does not work [#153](; - Problem generating deliverable [#157](; - Categories are duplicated in import [#158](; - Getting prob & impacts on operational risks [#161]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:0d93269dbd329d9e593d23f22f71e9d3adb6bf738f8508fcd595f0c2b279ca06 > * Mysql MONARC login: sqlmonarcuser:a1bf126400415576c1fc1c92695df9e2cc4bcc23483122eceac6635dd17c8d7b > > sha512sum: 18164f898ec38b2c20ec1f1a030044db57fcfea852617cde47dc0b1f314f410596dc66aaade7897f676207915dce5996183a317b9ec897d33371f9626e455257 > sha1sum: 72ca4f079281ad1fd5388391723a4a6d64d6b5d5 2019-05-28T06:37:18+00:00 MONARC v2.8.3 MONARC v2.8.3 2019-07-25T19:16:56+00:00 ### Enhancement - Some improvements in MOSP import - Some improvements in 3rd deliverable ### Fix - SOA is not imported [#166]( - Drag & drop in risk treatment plan fails after 1 change [#167]( - Underscore "_" is not considered as a special character in password reset [#169]( - Error when duplicating object [#171]( - Add objects in model/anr from common DB [#172]( - Composed objects in the library->position [#174]( - Import analysis -> conflict on uuid on objects [#175]( - FO > Knowledge base > OP risks [#177]( 2019-07-25T19:16:56+00:00 MONARC v2.9.0 MONARC v2.9.0 2019-08-23T12:05:43+00:00 ### New - each analysis can now integrate a record of processing activities in order to help you in your GDPR compliance efforts; - it is now possible to create and manage set of recommendations via the knowledge base of a risk analysis. Like for the security referentials (introduced in version 2.8.0), MOSP can now be used in order to [share recommendations]( ### Fix - Monarc 2.8.3 - invalid datetime format: 1292 [#179]( - various minor fixes and improvements. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.test:admin > * SSH login: monarc:password > * Mysql root login: root:fb839b36260022779d9de5e3aa266556550829959bbec8773d67c8f6b5455305 > * Mysql MONARC login: sqlmonarcuser:9502f6b02fc7d346e7daef5e3b2e3116b3096e06a10680160e08c95ff32e1556 > > sha512sum: 5975a79e8ceec2d6bf9eb62bc83f2cf926cac85f5e1ec87ba715e0ca3bf0dc28829676143074fcc77e76f9b01a1a8798589483abad1f0a9af3802a5322d9a397 > sha1sum: 5464cf1850293cb26768ff39d24e2b58a8c1212d 2019-08-23T12:05:43+00:00 MONARC v2.9.1 MONARC v2.9.1 2019-11-25T07:10:09+00:00 ### Enhancement - the backend of MONARC is now using Zend Framework 3 ([#15](; - MONARC code has been restructured to comply with PSR-2 standard; - updated the usage of the dependencies (Core and FrontOffice) from; - default initialization of the set of recommendations ([#183]( ### Fix - Error when importing OP risks with recommendation ([#191](; - fix editing of recommendations via the risk sheet ([#195](; - various fixes related to the management of recommendations and impact edition. > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:c03a114a788d1f5e85b6677c576079a36044f90c0043ec735dd174dde729297e > * Mysql MONARC login: sqlmonarcuser:b967d4f82e6f1571a52318203112d2862d1a0d36091fe669ce612517764b5a92 > > sha512sum: c1139d2232aa99aaa5e32d3033b2a3b4b9d4fa2fecd88d9850666c2cdfb6646d4339bc74863661dba8a7a04306aeee3416e2280c4a73ba94ad1d27ad8a3cd777 > sha1sum: bbf990d0647e02fd3838e79f23dab0b7ff96fbe9 2019-11-25T07:10:09+00:00 MONARC v2.9.2 MONARC v2.9.2 2019-12-09T13:04:32+00:00 - set composer.json to use dev-master instead of using fixed tag. 2019-12-09T13:04:32+00:00 MONARC v2.9.3 MONARC v2.9.3 2019-12-09T13:05:43+00:00 ### Fix - Configuration menu should not be scrollable ([#212](; - The type hint of parameter "theme" in method "setTheme" is invalid ([#211](; - Training VM does not show version number ([#210](; - library object duplicated ([#208](; - Drag and drop recommendations ([#206](; - Edit an asset in the library ([#205]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:d61b7bcb7f74d75c6288e781610500c9edc69785dea079fcfc89a760a1d78e2c > * Mysql MONARC login: sqlmonarcuser:70ad0142e19cfb0bc2990fcb5a742739deb924d66d5f1f50384db923b1d36cb6 > > sha512sum: fccbb92730bd82762d6b3b9cb3ee615ff0a5cc405aec3a96edceaa4ddef5f416e8201f0264be6f1cffbcfdc8cbb9cc797c690d82abf7d1bb7d2a911e8a9ee81f > sha1sum: f294ac2148f0aed5ea639e3d670132915d3bcb61 2019-12-09T13:05:43+00:00 MONARC v2.9.4 MONARC v2.9.4 2019-12-11T10:31:11+00:00 ### Fix - Users anrs permissions are not revocable / snapshots are displayed in the list ([#215](; - Drag and drop recommendations: fixes recommendations ordering ([#206]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:71ff9e3acc45b8983652283e4bfe74e37c51e85bff82875acbb0980fd2c2b270 > * Mysql MONARC login: sqlmonarcuser:f6fe3a0433c7c5875ebf722cc03f8e1a2094ce96ee5688b84fb2da598ac858d3 > > sha512sum: 76a81782bb9111568d6d535d3da8fe589f5e2597fccb1b37dbe5242da00cd3e96274d20207dcee7fd61d7666e652a9f66d233e0bd7d5b09b4b7b98004b1f94ea > sha1sum: b09bbfd0360b118b19d78d4843e23b3b67f580ab 2019-12-11T10:31:11+00:00 MONARC v2.9.5 MONARC v2.9.5 2019-12-19T08:50:35+00:00 ### Fix - Fixed the creation of the snapshots with empty comment; - Fixed the library categories management (creation of the new ones under root and sub categories) ([#216]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:34dbd8772adb1c2b8ab21a02fd29ac231e401c7b8f32c4411cde3551613ef109 > * Mysql MONARC login: sqlmonarcuser:31688c4f7dbdf1877aed935f91ba952420747876ba90afddffa8f247b4b27079 > > sha512sum: 991c7ee6f3734a6b52f9d06b2f60754ccb27935e7dd326f8cb0a72d53b695e580c717e617aee788cb5061ceef640ad6fa3a092df16a72f20d4512d2bd477a609 > sha1sum: 88f08235c8dda1d54f49ab3e6a38f4f5cc04ad44 2019-12-19T08:50:35+00:00 MONARC v2.9.6 MONARC v2.9.6 2020-01-02T07:41:17+00:00 ### Fix - Global object-> changes comment ([#224](; - Inconsistent id and global asset ([#225](; - Modification on global assets are not propagated properly ([#226]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:b8aaa7fde447d8280df6b7e4be2c8ee21e16549ba6c71ca54dbc80d2d407e696 > * Mysql MONARC login: sqlmonarcuser:9d1b9f6d5075f005f8cf08687fc258bb62569ea736534231d7d7696ba0b749df > > sha512sum: b88d849f8a0680544dd7e8be60b437caa1d0837a765c09d56ec1a8d609abe5ceaac8cf01fdbc2d7e6bb32933ab7a11d0f3275793e67847a47cb8af53ea5e846d > sha1sum: 86c567203a68bca75dc35a0699c082325f8b203e 2020-01-02T07:41:17+00:00 MONARC v2.9.7 MONARC v2.9.7 2020-01-07T08:22:24+00:00 ### Fix - Randomly deletion of recommendations ([#228]( - Upload a new delivery template ([#227]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:e5398216f1dc334b9564415684cbc41577432b03ebf95fffce9a00fc715fa423 > * Mysql MONARC login: sqlmonarcuser:86739ab22606d03d9abccc50d27c580433ae9946f1ee81b032894009ca74ca8e > > sha512sum: 616d5b0d3a7e472ea3ce56b5e24fc45bebcdc28eee0f926eb7930bc321bf72a0f2109913088dabc522a75653c1a1cff064c100cb06338489c5701ac516c1a0f7 > sha1sum: c70139f59aa7c1b5609050077829afd2cc990131 2020-01-07T08:22:24+00:00 MONARC v2.9.8 MONARC v2.9.8 2020-01-13T05:56:24+00:00 ### Fix - Library categories management issues ([#221](; - Library -> global asset -> delete asset ([#229](; - Library -> asset -> Asset used in the risks analysis ([#218]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:664a42bc0a871b04a965448dd859b8fb313a9a60eff7e417184f7f788e9fcda4 > * Mysql MONARC login: sqlmonarcuser:8b9199904cebe3f4825243165fe4b45fa8c516f817e10399d8726fb9efb48805 > > sha512sum: b3c67159931bf14e610d347a938c82bd5e85948687753272fdade72161642e82486828c3c8f1fb1fdee6a0002ffdfc8da583a22de87ba899fe4372eacf73c964 > sha1sum: d327d46c5136c8b9468aff69d8a7ee1250f9fbb5 2020-01-13T05:56:24+00:00 MONARC v2.9.9 MONARC v2.9.9 2020-01-20T20:22:32+00:00 ### New - Give the possibility to administrators to create new account and directly assign a temporary password for the new account ([#236]( ### Fix - Increase size of the fields related to Record of Processing Activities ([#230](; - Duplication of risks in Deliverable -> appendix D ([#233](; - Error during modification of information risk ([#234](; - It is no more possible to change the status of a user ([#237]( 2020-01-20T20:22:32+00:00 MONARC v2.9.10 MONARC v2.9.10 2020-01-29T14:15:30+00:00 New feature: - Implement tiered indexing in Annex D of final report Included the following fixes: - BackOffice object export error - Import error 2020-01-29T14:15:30+00:00 MONARC v2.9.11 MONARC v2.9.11 2020-02-24T16:02:21+00:00 ### New - added users creation command ([PR 27](; - backend has been migrated from Zend Framework to Laminas ([#249]( ### Fix - The description area of the shelf life is too fair at the character level ([#252](; - In the description of destinations area; info is not kept after registration ([#253](; - [GDPR module] Issue when creating a new recipient with default values ([#254](; - Get the list controls in BO ([#256](; - fix: improved performance when drag and dropping assets ([ff473d9]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:f7d45578f892f39719ad33e83aa687547baf89a4d3f70cf15838bee50f1f1b07 > * Mysql MONARC login: sqlmonarcuser:7d7b72a8ff4fe51d5ee034bef3ddde0a8a7a055258cfdfde953010b448f446f0 > > sha512sum: d25e14433a2730f6f7387cf6786faadcf45b767659f2d1cf1872d3b7f5afafd0142813a96d0036e14a9d5c3af68984f56342033278b8b22b61cb8851439743e4 > sha1sum: 87e1ee746c86ae679b83c8c0257c607f95f167b5 2020-02-24T16:02:21+00:00 MONARC v2.9.12 MONARC v2.9.12 2020-03-20T14:40:53+00:00 ### New - batch import of information risks from csv/xlsx file ([#246]( ### Enhancement - use a better encryption method for the export of objects and analysis ([#260]( ### Fix - Remove comment field of threat in export object of library ([#245]( - Edition and creation of operational risk linked a tag in use on risk analysis ([#262]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root: 978ac8bb032bb1c46ebec2d7aacb15174653ff71bf902eca440430db8f67537d > * Mysql MONARC login: sqlmonarcuser: 508f2bc366c78279e64ee369f61cce0e32d0a7046c27e52d62308c18e2ef0316 > > sha512sum: 50d3c50a5a451989df6b75667dcd4a96cbcec0e96ac27ecf22de482ccd8ecd7d9b625abe65162f6954f026128436a437003aff3b2d0d05036722e4a7a868d1b5 > sha1sum: 3b2d1ec34728e997d48389d2f6a24b3765ceb19a 2020-03-20T14:40:53+00:00 MONARC v2.9.13 MONARC v2.9.13 2020-04-14T10:45:51+00:00 ### Fix - Reset positions of recommendations during assets drag-n-drop ([#261]( - Change http response code if authentication is failed ([#266]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:abb7667b70d3ab49e9d0c454f818125eaeda05e3a3d19b0239bbee3b22b52dbc > * Mysql MONARC login: sqlmonarcuser:50b49cfd3d8aac9a99cbda69a75bcab52db9563c143f5065ce89b629ec6c8e21 > > sha512sum: a3772bc896da0ed5104c39014aee207787382db02daaeb030e88ac4f4eaa8e830065b6f685139160ecb5636fbd8ff519cd4df4ce24d7ac2d01f2c85a2d7294f2 > sha1sum: 6e31dec4b937ba0070a15cce47d312d8c153a9d0 2020-04-14T10:45:51+00:00 MONARC v2.9.14 MONARC v2.9.14 2020-04-24T10:54:53+00:00 ### Fix - "Edit impacts" in version 2.9.13 ([#273]( - Duplicate assets ([#279]( - Translation "Vulnerabilities" in the Knowledge Base ([#275]( > Login and passwords for the MONARC VirtualBox demo image > * MONARC application: admin@admin.localhost:admin > * SSH login: monarc:password > * Mysql root login: root:029f48380a1421838ac2a543771557a90f3ec4621048002afa3a33abc0c83659 > * Mysql MONARC login: sqlmonarcuser:f032789bfae64a393ca571b45805939409a08ab53af5ca6cd55d6e7ff9f1b70d > > sha512sum: f077428ef6463907f1e1aa0c8027caa5df9dd3a54ebf345b9fb2da3e0ffe7e27ff63eb7b73c070056750d236144a1cb242f8f57da0db556e68d1fe787112157b > sha1sum: 460210017402ce65907f7eef44b5e00cc8b600b6 2020-04-24T10:54:53+00:00 MONARC v2.9.15 MONARC v2.9.15 2020-06-02T14:04:41+00:00 ### Fixes - Impossible to export an analysis when a user has deleted a category of a measure ([#282]( - Matched referentials cannot be unlinked ([#289]( - Orphan categories of controls on import function ([#290]( - Improvements and fixes for German translations ([#293]( - Dashboard Diagrams "No Data" 2.9.14 ([#294]( 2020-06-02T14:04:41+00:00 MONARC v2.9.16 MONARC v2.9.16 2020-08-14T10:45:43+00:00 ### Fixes - Risk treatment plan comment delete date. ([#298]( - Read Only User logout during risk treatment. ([#300]( - Importing operational risks, the rolfRisk and riskCacheCode fields does not match the knowledge base. ([#303]( - Duplicate/snapshot sets always same amv uuid for all instances_risks. ([#304]( - Import with the same threat linked to a specific risk doesn't work. ([#305]( - Creation of models on BackOffice with risks in analyse. ([#306]( - Add new deliverable model for record of processing ([#307]( 2020-08-14T10:45:43+00:00 MONARC v2.10.1 MONARC v2.10.1 2020-12-17T19:58:35+00:00 ### Fix - Detaching of recommendations doesn't work ([#314]( - Record of processing activities creation from an existing. ([#315]( - ANR_DOES_NOT_EXIST Error while creating new users. ([#319]( ### New - Analysis statistics development (Epic) ([#268]( 2020-12-17T19:58:35+00:00 MONARC v2.10.2 MONARC v2.10.2 2021-02-25T14:39:09+00:00 ### Fix - Export an asset ([#325]( - Snapshot restore ([#326]( - Multiple login sessions per user ([#333]( ### New - Enable or disable the statistics sharing per analysis ([#329]( > Login and Passwords for MONARC App and VirtualBox demo image (format: username:password): > * MONARC application: admin@admin.localhost:admin > * SSH login (Ubuntu credentials): monarc:password > * Mysql root login: root:4274086f0ea9b0356d295a4597de55cd55fb3d3f718d76626019213b8031fdf6 > * Mysql MONARC login: sqlmonarcuser:26706142cf41059ef42eecb344d9b777ec806ceedc7ce1b147132f972f08cc1f > > sha512sum: bcf0e16fed207b3206a8336919c4422907e2792ce0969b9e87eba642090e7c4bf24a8cf3ac3370a07a6cb8e93c2d6caf775396e822995b403370173cb0f71203 > sha1sum: 5c5cd0697c6b8ec470d1bfeaa12fc101a059bfc0 > > MONARC is available on port 80. > MONARC Stats Service is available on port 5005. 2021-02-25T14:39:09+00:00 MONARC v2.10.3 MONARC v2.10.3 2021-05-10T15:51:29+00:00 ### New - Implement the UI language management ([#318]( - Implementation of the library objects import and assets export from/to MOSP ([#320]( - Possibility to export items from the Knowledge Base ([#321]( - Send MONARC version to Stats Service ([#341]( ### Fix - [Front Office] export of measure related to "amvs" stoped working since v2.10.1 ([#340]( ### Enhancement - Improve the import speed of analyses and instances (*partially done*). ([#248]( 2021-05-10T15:51:29+00:00 MONARC v2.10.4 MONARC v2.10.4 2021-06-24T13:22:51+00:00 ### Fix - Foreign Key Error by when deactivating information security risks. ([#358]( - Dashboard cartography error for risk lists. ([#359]( - [FrontOffice] Snapshots creation error. ([#362]( ### Important Note Before updating your monarc version to 2.10.4 please make sure you have `php -v` v7.4 and `composer --version` not less then 2.0.13 on your server (if not please execute `composer self-update`, it might require to run it with `sudo`). The VirtualBox demo image is available on MONARC website [release page]( 2021-06-24T13:22:51+00:00 MONARC v2.11.0 MONARC v2.11.0 2021-09-02T12:29:58+00:00 ### New - having the possibility to define custom scales for operational risks ([#353](; - introduction of the risk context and the risk owner ([#21](, [#186]( ### Fix - Could not read from remote repository ([#365](; - some files in script do not have the correct permissions ([#364]( ![Screenshot_20210902_133851]( ![Screenshot_20210902_134102]( ![Screenshot_20210902_142720]( 2021-09-02T12:29:58+00:00 MONARC v2.11.0-p1 MONARC v2.11.0-p1 2021-09-06T11:03:55+00:00 [small fix]( in the zm-client dependency for the import of risks. 2021-09-06T11:03:55+00:00 MONARC v2.11.1 MONARC v2.11.1 2021-10-26T10:37:30+00:00 ### New - Add import of referential mapping from MOSP ([#391]( ### Fix - Subsuming CIA criteria according to the maximum criteria does not work ([#339]( - Incorrect sum and list of risks under the secondary assets ([#367]( - If impact adjustments are made not only at the level of the primary assets but also at the level of the secondary assets, these assets are listed more than once ([#387]( - Recommendation status change error in the Knowledge Base ([#393]( - Import issue of setting operational risks values ([#394]( - Fix possible circular iteration of the instance root -> parent -> child rendering ([#395]( - Mathematical representation of large numbers in the dashboard ([#398]( 2021-10-26T10:37:30+00:00 MONARC v2.11.1-p2 MONARC v2.11.1-p2 2022-06-15T06:56:04+00:00 2022-06-15T06:56:04+00:00 MONARC v2.12.0 MONARC v2.12.0 2022-06-20T12:44:13+00:00 ### New - [compliance scale]( - [metadata assets]( - [two-factor authentication]( - new build deployment is available and based on GitHub Actions ### Fix - [Stats provider] removed the leading slash in the URI ([e7dfba1]( Details about upcoming related releases: 2022-06-20T12:44:13+00:00 MONARC v2.12.1 MONARC v2.12.1 2022-06-22T07:39:21+00:00 2022-06-22T07:39:21+00:00 MONARC v2.12.2 MONARC v2.12.2 2022-06-29T07:20:25+00:00 2022-06-29T07:20:25+00:00 MONARC v2.12.2-p1 MONARC v2.12.2-p1 2022-07-04T08:56:31+00:00 2022-07-04T08:56:31+00:00 MONARC v2.12.2-p2 MONARC v2.12.2-p2 2022-07-07T10:44:13+00:00 Fixed an issue with sortable 1.15.0 2022-07-07T10:44:13+00:00 MONARC v2.12.2-p3 MONARC v2.12.2-p3 2022-07-07T12:42:37+00:00 2022-07-07T12:42:37+00:00