Find the insights and best practices about our product.
2026.10.1 Release Notes

Release #: 2026.10.1

Release Date: October 8th, 2026

What's New

This release adds vendor management and custom vendor fields, vendor endpoints in the Public API, and JSON import for Bills of Materials. It also changes the format of CSV exports, improves the Arena findings view, expands the foundation model catalog, and includes several bug fixes.

Vendor Management and Custom Vendor Fields

You can now add, edit, and retire vendors from My Vendors, so a vendor no longer has to start with an AI Card request. Select Add Vendor to record a vendor's name, legal name, primary domain, website, and description. If the new vendor resembles an existing vendor by name or domain, a warning links to the existing vendor, and the new vendor is still created. Edit Vendor and Retire Vendor are on each vendor's detail page. Renaming a vendor can unlink it from AI Cards already received under the old name, and the edit form warns you before you save. A retired vendor and its AI Cards no longer appear in Cranium or count toward the summary tiles, but they aren't deleted. You can't reactivate a retired vendor. Organizations that have sent you AI Cards but aren't set up as vendors still appear in My Vendors, and you can't edit or retire them until you add them as vendors. AI Card publishers that belong to the same vendor now appear as one row with combined counts, so you may see fewer rows than before. Adding, editing, and retiring vendors requires the vendor Create, Update, or Delete permission.

Custom vendor fields record the information your organization tracks for each vendor, such as a supplier number, risk tier, or contract owner. Define fields from Manage Custom Fields on My Vendors. Each field has a label and a key, and you can mark a field as required or unique. A field's key can't be changed once saved. Drag fields to set the order they appear on the vendor form and detail page. In table view, Customize Table adds custom fields as columns in the My Vendors list. Each user's column choices are saved separately, and custom columns can't be sorted. Field values are text up to 400 characters, and a tenant can have up to 50 active fields. When you retire a field, it and its values are hidden everywhere, and you can't restore the field.

Vendor Endpoints in the Public API

The Public API now supports listing, looking up, creating, updating, and retiring vendors. Vendor records can stay in step with a procurement or third-party risk management system without anyone opening Cranium. The vendor list is cursor-paginated, so a sync can read the full list once and then pass updatedAfter to fetch only vendors changed since a given time. Each action requires its own permission, and holding one doesn't grant another. Possible duplicates never block a valid create request. If the new vendor resembles an existing vendor by name or primary domain, the response lists those vendors for review. An update replaces the full vendor record, so the update clears any field left out of the request. Retiring a vendor through the API is permanent and doesn't remove AI Cards, BOMs, or vulnerability data received from that vendor.

The vendor endpoints also read and write custom field values through a customAttributes object, keyed by field key. Values must be JSON strings. Custom values merge on update. Leave customAttributes out to keep the stored values, or send a key with an empty value to clear it. You can define custom fields only in Cranium, not through the API. The publisherNames and sharedAiCardCount fields appear on every vendor but aren't populated yet.

Import a Bill of Materials from a JSON File

Select Import on the BOM details page to replace an existing Bill of Materials with the contents of a JSON file, such as a BOM you exported after a CodeSensor scan and cleaned outside Cranium. The file must use the same format as the BOM export and be 5 MB or smaller. Cranium validates the file and lists specific errors if anything is wrong.

The import replaces every item in Technologies, Models, Datasets, and Infrastructure, and prior versions remain in Version History. It also clears the BOM's VCS integration and repository references and makes the BOM self-attested, so a BOM created with CodeSensor can no longer be rescanned. A new vulnerability assessment runs automatically against the imported items. Import is unavailable while a scan of the BOM is queued or running. CycloneDX and SPDX files aren't supported, and the creation wizard can't create a new BOM from a JSON file.

CSV Export Changes

Two changes to CSV exports can affect scripts and integrations that read the files automatically. In the Technologies vulnerability export, the Repository Name column now contains only the repository name instead of the full integration, organization, and repository path, and the organization moves to a new Repository Organization column. Every CSV export also adds an apostrophe to the start of any text cell that begins with =, +, -, @, a tab, or a carriage return, which stops spreadsheet applications from treating the cell as a formula. Numeric cells are unchanged. Spreadsheet applications hide the apostrophe, but scripts that read the raw file see it, so @angular/core appears as '@angular/core.

The Technologies vulnerability export also adds three columns after all existing columns. Project Name shows the Azure DevOps project or GitLab group, AI System Name lists the linked AI systems separated by semicolons, and Repository Organization shows the GitHub owner, Bitbucket workspace, or Azure DevOps organization. A column is blank where the source control system has no equivalent. On the Vulnerabilities page, the Technologies table adds Project Name and Repository Name columns before AI System.

Arena Findings View Improvements

Vulnerable attack category cards on the Model Threat Analysis page now rank by attack success rate across all results, not only the current page, so the most exploitable categories always appear first. The label under each category name now shows the OWASP weakness name instead of "Attack Type." When a category ran only one test type, the other ring appears dashed with a dash in place of 0%, so an untested result can't be mistaken for a 0% success rate.

Expanded Foundation Model Catalog

The catalog Cranium uses to classify discovered AI models has grown from about 3,600 to about 4,100 foundation models, and from about 16,000 to about 19,000 recognized name variants. Newly discovered models that match the catalog receive a model type, family, and standardized name, including families that were previously missing, such as BERT, Stable Diffusion, Claude 2, and Gemini 1.0. Only models discovered after this release are affected, and models already classified aren't reclassified.

Bug Fixes

  • Fixed an issue where edits to the name or description of an item in a self-attested BOM were discarded. Edits now save, and edits lost before this release must be re-entered. Item names in scanned BOMs can no longer be edited, since the next scan sets them, but their descriptions can still be edited.
  • Fixed an issue where a BOM rescan after a CodeSensor version upgrade showed a "DatabaseError" message even though the rescan started successfully.
  • Fixed an issue where BOM status appeared incorrectly on AI System pages and in the AI Card publish picker. BOMs could show no status, and a published BOM could show "In Progress" indefinitely. Status now matches the BOM list, and a published BOM always shows as Completed, including on AI Cards already published.
  • Fixed an issue where CodeSensor scans skipped JavaScript .mjs and .cjs files. These files are now scanned and counted as JavaScript. Because scans are incremental, existing .mjs and .cjs files appear in results once they change or after a full rescan.
  • Fixed the Detect AI scan form, which said that leaving the scope fields blank would scan everything. It now states that a blank Oldest Last Commit Date applies a 365-day default. Set the date to include repositories with older commits.