Changelog
We ship updates regularly. Install the app to receive update notifications via Atlassian Marketplace.
v4.3.0 15 April 2026 · marketplace release
- Approved and published on Atlassian Marketplace (ECOHELP-123535, 15 April 2026)
- Bulk approve — select terms in review and approve them in batch (shipped 5 April)
- Context-aware bulk actions — only valid status transitions shown per filter (shipped 5 April)
- Dashboard screenshot refreshed to reflect current UI (5 April)
v4.2.0 5 April 2026
- Deep code review — DRY refactoring across backend and admin UI (4 review passes, 26 fixes)
- ALCOA+ Attributable + Contemporaneous — every term edit records actor (
contentEditedBy) and ISO-8601 timestamp; audit-trail write failures now surface a warning instead of being silently dropped - Test count expanded from 69 to 77 automated tests (formula-injection sanitization, CRLF, trailing-comma, null/undefined input)
- Scanner performance —
scanPageuses cached term lookup (~200ms vs ~7.5s) - Forge KVS upgraded to 1.6.0 with strict schema validation (
findingsTruncated,contentEditedBydeclared) - ESLint + pre-commit hook + CI lint — automated code-quality gates on every commit and PR
- Major dependency upgrade — React 18, Atlaskit css-reset 7, Forge API/KVS/Bridge, Babel, Jest 30, ESLint 10
v4.1.0 29 March 2026
- Dependabot configured for daily dependency updates, aligned with Atlassian SLAs
- Telegram notifications for Dependabot PRs and security audit failures
- npm audit fix — resolved brace-expansion and yaml moderate vulnerabilities
- Forge KVS bumped 1.4.0 → 1.5.0;
@babel/preset-env7.29.0 → 7.29.2; jest 30 / babel-jest 30 / eslint 10
v4.0.0 25 March 2026 · privacy & security hardening
Resolves Atlassian Marketplace review feedback on the v2.5.0 submission of 21 March 2026. Renumbered from the v2.x line to mark the privacy/security baseline used for the live listing.
- Resolver calls migrated from
asApp()toasUser()for correct permission scoping - Customer DPA, security policy, sanitized error logging, security.txt
- Security audit + tests CI pipeline (push, PR, weekly cron);
undiciupgrade for high-severity fix - "How It Works" page documenting scanner logic and architecture
v2.5.0 21 March 2026 · first marketplace submission
- Initial submission to Atlassian Marketplace review (paid app licensing plumbing, ToS rewrite with indemnification + €100 minimum liability cap, GDPR-aligned privacy policy)
- Dark theme toggle, space selector dropdown, AI support chatbot
- Bug fixes: double-encoded CQL in user search, external links in Forge iframe, phantom audit records in bulk operations, resolution badge crash on missing theme
v2.0.0 – v2.4.0 10–20 March 2026 · internal iterations
- Internal-only iterations between MVP and first Marketplace submission. Includes 8 enterprise-scale fixes from expert audit (20 March), code review hardening, and audit-trail integrity work.
v1.0.0 (MVP) 10 March 2026 · internal pre-release
- Term management, compliance scanner, audit export
- Four-eyes approval workflow with change justification and stale-approval detection
- Version history with full audit trail
- CSV import/export, search, roles, error handling
- Enterprise-scale scanner — pre-compiled regex, fast-reject, paginated INDEX (63 tests at this point)
Note on numbering: the app does not embed a semantic version in source. Version labels above (v1.x–v4.x) reflect the Marketplace-side version assigned to each submitted bundle. Internal v3.x bundles were not separately submitted — the next Marketplace-visible submission after v2.5.0 was v4.0.0.
Related
Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
Security whitepaper — Forge architecture, SOC2/DORA/NIS2/GDPR/FDA 21 CFR Part 11 posture
Compliance guide — what auditors check and how Compliance Glossary maps to real regulatory standards
Documentation — installation, admin UI, four-eyes workflow, scanner, CSV import/export
AI Act terminology governance — Article 3 definitions managed as a versioned glossary
DORA terminology — ICT risk, third-party, and incident taxonomy for financial-entity teams