Skip to Content

SAMURAI 4.7

Released July 9, 2026.

Features

  • AI: feed recently-rejected proposals to the council as decline context
  • AI: keep rejection tombstone conservative + observable
  • AI: operator-tunable retention for terminal memories
  • AI: state_reason — why a memory is in its current state
  • Ai Tools: shared list-query layer — filter/fields/page + iteration hints
  • Ai Tools: temporal sync-lag annotation + at_change snapshot reads
  • Ai Tools: trigger-condition descriptions + schema enums + protocol example
  • Apic Ui: parse src_port/dst_port search tokens end-to-end
  • Apic Ui: render contract lookups at top-of-page notification stack
  • Apic Ui: single-row contract badges + shared NotificationBanner for lookups
  • Apic Ui: Source/Destination Port in the Add-Filter dropdown (both tabs)
  • Cisco ACI: contract port search matches unspecified-port (permit-any) filter entries
  • Cisco ACI: entry-aware Filters-tab search + source-port contract search (#972 #973)
  • Cisco ACI: plain-text filter search is entry + port aware
  • Cisco ACI: selected tenant as a URL path segment, not ?tenant=
  • Datatable: animate expandable rows open + closed
  • Filters: ACL operators (eq/in) on action/protocol
  • Filters: eq/ne/in operators across all datatables
  • Filters: generic filter-catalog registry + migrate Memories
  • Filters: migrate ACL (router+switch) field catalog to backend
  • Filters: migrate APIC Contracts field catalog to backend
  • Filters: migrate Endpoints to backend catalog + operators
  • Filters: migrate Routes field catalog to backend
  • Filters: numeric operators gt/lt/gte/lte on Endpoints vlan
  • Filters: operator engine + Changes filter-field catalog backend (#980 #981)
  • Filters: operator-aware AdvancedFilterBar + backend metadata on Changes
  • Filters: Routes operators (eq/in) on categorical fields
  • Cisco FTD/ASA: canonicalize gt/lt service operators to searchable port ranges
  • Cisco FTD/ASA: make services: search any-aware for unrestricted access rules
  • Palo Alto: make service: search any-aware for permit-all rules
  • Policy Analyzer: Access rules tab (browse the actual rules)
  • Policy Analyzer: ACI access-policy explorer + host search (reuse topology)
  • Policy Analyzer: auto-select the first device on open
  • Policy Analyzer: canonical PolicyRule model + pure Palo adapter
  • Policy Analyzer: compute App-ID / users / URL categories
  • Policy Analyzer: device + tab in the URL path (/policy-analyzer/:device/:tab)
  • Policy Analyzer: expand anomaly/optimize findings to show the actual rule(s)
  • Policy Analyzer: export button on every tab (CSV/XLSX/HTML/PDF)
  • Policy Analyzer: extend the analyzer to Cisco FMC (multi-vendor)
  • Policy Analyzer: extend to Cisco ACI/APIC (order-free contracts)
  • Policy Analyzer: extend to Cisco FTD (deployed running-config)
  • Policy Analyzer: extend to FortiGate (adapter, unit-tested)
  • Policy Analyzer: frontend page surfacing risk/zones/anomalies/hygiene
  • Policy Analyzer: hit-stats capture, PermPolicyAnalysis, config collections
  • Policy Analyzer: merge adjacent same-action rules
  • Policy Analyzer: merge vendor/device/scope into one device-focused control on the tab row
  • Policy Analyzer: named level dropdowns for zone trust/criticality
  • Policy Analyzer: NGFW scoping narrows risk breadth
  • Policy Analyzer: one flat device list, drop the vendor field
  • Policy Analyzer: OpenAPI 3.0 contract, served live
  • Policy Analyzer: optimizer - derived removal/cleanup recommendations
  • Policy Analyzer: Palo hygiene runner + gated trigger endpoint
  • Policy Analyzer: per-framework compliance report
  • Policy Analyzer: per-policy/section filter (drill into one FTD cluster)
  • Policy Analyzer: persist active tab in the URL (?tab=)
  • Policy Analyzer: pure firewall hygiene evaluators
  • Policy Analyzer: relational anomaly engine + negate flag
  • Policy Analyzer: resizable policy drill-down sheet + full-row expand
  • Policy Analyzer: scope FMC findings by access policy (FTD cluster)
  • Policy Analyzer: server-side filter/sort/pagination + AdvancedFilterBar (all tabs)
  • Policy Analyzer: sigma.js graph visualization (ACI + firewalls)
  • Policy Analyzer: split anomalies into actionable vs advisory
  • Policy Analyzer: Tier-2 exact effective-space engine (union coverage)
  • Policy Analyzer: triage + group relational anomalies
  • Policy Analyzer: vendor-native config candidates + reachability diff
  • Policy Analyzer: YAML policy-as-code compliance packs
  • Policy Analyzer: zone rating + per-rule risk scorer (pure)
  • Policy Analyzer: zone rating storage + risk endpoint + zone discovery
  • Policy Analyzer: zone-aware compliance (CDE least-privilege checks)
  • Policy Analyzer: zone-pair baseline matrix + segregation check
  • Policy Analyzer: zone-pair segregation matrix (AlgoSec-style)
  • Policy Graph: contracts (ACI) / rules (firewall) as clickable nodes
  • Policy Graph: node click opens a policy-analysis panel
  • Policy Graph: searchable, contract-first node panel with filter->entry drill-down
  • Policy Graph: unify the ACI + firewall graph palette
  • UI: animate role-permission group collapse + wider role/user dialogs
  • UI: show read-only provenance in the Edit memory dialog

Bug Fixes

  • Apic Ui: badge single-row means per-badge, not per-cell
  • Cisco ACI: stop tenant-switch render loop on filtered tabs
  • Cisco ACI: use a space (not a literal NUL) as the filter-key separator
  • Ci: regenerate frontend lockfile in linux node:22
  • Filters: add not_contains operator + enum-first operator ordering
  • Filters: honest fallback operators for operator-less fields
  • Filters: preserve operators through per-field URL round-trip + browser e2e (#982 #983)
  • Palo Alto: attribute clone+rename rules + surface admin source IP
  • Policy Analyzer: ACI per-filter deny + vzAny relations (fidelity review)
  • Policy Analyzer: conform page to platform design system
  • Policy Analyzer: correlation requires shared App-ID / URL-category scope
  • Policy Analyzer: embed finding rule cards server-side
  • Policy Analyzer: graph renders — aggregate parallel contract edges
  • Policy Analyzer: make the device selector a single direct dropdown
  • Policy Analyzer: soundness fixes from high-effort code review
  • Policy Analyzer: vendor selector as a dropdown, not a segmented control
  • Policy Analyzer: zero_hit uses Palo native last_hit, not first-capture
  • Policy Analyzer: zones are a match dimension in shadowing analysis
  • Policy Graph: firewall graph crash on parallel zone edges (zone:any->zone:any)
  • UI: header leading icons only on Panels-section pages
  • UI: make the whole pending-review bar clickable
Last updated on