Back to Blog
September 30th, 2026

Developer Roll Up: September 2026

Picture of Christopher Luft
Christopher Luft

Co-founder and CCO

blog post header image

September's two web app releases each took on one big job. 6.3.0 made detection engineering something you can test, with rules getting a full testing workspace, a logic tree, and a flood warning on save. 6.4.0 opened the LimaCharlie Bots workspace and gave Code Security a front page that reflects real scan coverage. Four sensor releases added a set of new investigation commands and fixed a lot of crashes: Linux and macOS now shut down cleanly instead of reporting every restart as a crash, and when a real crash happens, the report has enough detail to diagnose it.

Detection rules you can test before you trust them

The rule page's stored tests and replay panel are now a single fullscreen testing workspace, replaying every stored case against the rule as edited and reporting pass or fail for each. A rule logic tree draws the detect block as a boolean tree with the replay evaluation on it, and clicking any operation shows what it read, expected, and got. Saving an enabled rule replays the last hour of telemetry in the background, warning at 100 or more matches an hour so an overly broad rule surfaces in seconds instead of hours. The save dialog no longer offers "Save anyway" on failing tests, and rules can now be edited as YAML or JSON with import and export.

Cloud Security: endpoint agents as a vulnerability source

A new Policies tab turns on the endpoint-agent vulnerability lane, so CVEs reported by a LimaCharlie agent become Cloud Security findings. Findings now show exploit band, fix availability, observing lane, and CISA's KEV due date, with unknown shown where the platform didn't report a value. VEX and SLA policy editors let you mark a finding as not affected or set the SLA clock behind every due date, and a dedicated Coverage page reports each lane separately. A new Integrations tab documents ingestion options that were previously API-only.

LimaCharlie Bots get a workspace

A personal workspace at /sessions/workspace lets you switch between named bots, build groups, and watch them hand work to one another, with live progress on each. New chat and history let you start a bot on a clean runtime while keeping its configuration and memory. A starter team of six LimaCharlie specialists, including Sensor Fleet Operator, D&R Rulesmith, and LCQL Hunter, replaces the generic roster.

Code Security grows up

A new Overview tab leads with a prioritized fix queue, showing scanner coverage and evidence tracing code to image to running workload. The UI now reads your GitHub App's actual permissions instead of guessing, GitLab and Bitbucket Cloud can be connected from the provider wizard, and pull-request checks now fire on push and on base-branch changes.

Query Console and the rest of the app

The Query Console holds far less memory, releasing rows far from the viewport and re-fetching them on scroll-back. The Detections live feed merges new batches into the sorted list instead of re-sorting everything, and Event Collection now reads its event types from the extension itself, picking up 40 events the bundled list was missing.

Sensor: new commands for investigation

dir_find walks a directory tree reporting file metadata and hashes, and file_grep searches file contents for literal patterns. container_list inventories containers and images on Linux, and repo_list ties a repository to every host that has it cloned. usb_list_devices lists every USB device by class, manufacturer, and serial, and restart_core restarts the sensor on demand on Linux and macOS.

Sensor: crashes that stop happening, and reports when they do

Linux and macOS sensors now shut down cleanly when stopped. Termination signals weren't being handled, so every service stop, restart, reboot, and upgrade was reported to the cloud as a crash, accounting for nearly all the crash volume from those platforms. Crash reports now carry stack trace, loaded modules, and fault detail on all platforms, and a bug that reported real crashes as clean exits is fixed.

Sensor: smaller, and self-repairing on Linux

Debug information now publishes separately instead of shipping to endpoints, shrinking the Linux service binary about 45% and the macOS one about 38%. Linux .deb and .rpm packages now restore a missing service definition on upgrade, and a bug that permanently lost kernel acquisition after a force-kill is fixed.

Full release notes for web app 6.3.0 and 6.4.0 are on Docs, along with sensor releases 5.3.8 through 5.3.11.