Changelog

Latest updates and improvements to StacksAtlas.

v1.2.7

Latest Release

Released May 9, 2026


Enterprise Identity & SSO
  • Production-Grade OIDC Handshake

    Full OpenID Connect support for Google, Azure AD, and Okta. Features a robust 'Capture-and-Forward' redirect engine for complex NAT/Proxy environments.

  • LDAP/Active Directory Integration

    Added native bind-based LDAP support with JIT provisioning, allowing enterprise users to log in using existing corporate credentials.

  • UI-Driven Role Mapping

    Introduced a dynamic engine to map external groups (OIDC claims, LDAP DNs) directly to StacksAtlas permissions (Admin, Standard, Viewer).

  • Pre-flight Connectivity Testing

    Integrated server-side diagnostic tools to verify OIDC metadata and LDAP bind credentials in real-time before saving configurations.

Security & RBAC Hardening
  • Granular Endpoint Authorization

    Hardened system security by enforcing strict RBAC policies on traceroute, diagnostics, and management tools.

  • Viewer-Safe UI Architecture

    Intelligent UI state management that automatically disables destructive actions for View-Only users, preventing unauthorized network changes.

  • Dedicated 'Me' Profile Management

    Launched a secure self-service profile endpoint, allowing all users to manage their personal alert preferences without administrative rights.

  • Write-Only Secret Security

    Implemented a masked 'Write-Only' pattern for sensitive configuration fields, ensuring Client Secrets are never exposed in the UI.

Outbound Webhook Alerts
  • Multi-Provider Webhook Support

    Native payload formatting for Slack (Block Kit), Discord (Rich Embeds), and Microsoft Teams (Adaptive Cards 1.5+). Allows for deep integration into enterprise notification workflows.

  • Resilient Delivery Engine

    Implemented exponential backoff with jitter and a smart Circuit Breaker mechanism to pause failing endpoints, ensuring appliance performance remains stable during external outages.

  • On-Demand Connectivity Testing

    Added a one-click 'Test Payload' feature and real-time delivery history logs directly in the management UI for instant verification of external alert routing.

  • Secure Webhook Management

    Features encryption-at-rest for URLs, masked secret management, and optional HMAC-SHA256 signing for cryptographically verified payload integrity.

v1.2.6

Released April 26, 2026


Engine Stability & Throughput
  • Thread Pool Starvation Resolution

    Implemented a 'Ping-First' strategy for subnet sweeps, eliminating the 10-second hang caused by blocking ARP calls.

  • mDNS Overhead Optimization

    Reduced mDNS listen windows and increased scan intervals to 5 minutes, significantly lowering network 'tax' during discovery.

  • Permanent Diagnostic Instrumentation

    Integrated granular phase-timing into the engine via Debug logs, enabling instant performance audits directly from the Dashboard UI.

  • Real-Time Debug Toggle

    Introduced a 'Debug Mode' switch on the Logs page for instant, verbose diagnostics without requiring a service restart.

Feature Restoration
  • Security Audit Real-Time Sync

    Restored the background security scoring engine to the main sync loop for live vulnerability updates.

  • Timeline & System Events

    Re-implemented event logging for device discovery, roaming, and status changes to restore full history visibility.

  • Health Metric Persistence

    Restored Latency History and Stability Score increments to ensure accurate long-term health analytics.

SIEM & Enterprise Visibility
  • Native Syslog (RFC5424) Sink

    Introduced real-time event streaming to SIEM platforms like Splunk and Elastic, enabling enterprise-wide security correlation.

  • Unified Infrastructure Management

    Consolidated Network Ports and SIEM configuration into a single, high-authority 'Appliance Infrastructure' section with atomic restart controls.

Licensing & Offline Resilience
  • Zero-Secret Public Activation

    Migrated to a secure, public licensing handshake. Master API Keys are no longer stored within the appliance, significantly hardening the security posture.

  • 60-Day Offline Grace Period

    Introduced a tiered offline verification system (30-day soft warning, 60-day hard expiry) to ensure business continuity in remote or air-gapped sites.

  • Security Backdoor Removal

    Completely eliminated legacy 'Mock Mode' bypasses, ensuring mandatory, authoritative validation for all production environments.

Bug Fixes & Hardening
  • LiteDB Password Portability

    Fixed a cross-platform encryption issue preventing database migration between Windows and Docker/Linux.

  • APIPA Hijack Protection

    Hardened auto-detection to ignore 169.254.x.x subnets while keeping them manually selectable.

v1.2.5

Released April 25, 2026


Identity & Architecture Authority
  • Centralized Identification Authority

    Eliminated identity 'ping-pong' by centralizing all device classification logic into a single, authoritative reconciliation engine.

  • Confidence-Based Specificity Locking

    Implemented a hierarchical identity system that prevents low-confidence discovery data from overwriting manual names or high-confidence fingerprints.

  • Stateless API Decoupling

    Refactored the core API infrastructure into a modular, service-oriented architecture for significantly improved reliability and cold-start speed.

Enterprise Security Hardening
  • 256-bit Database Entropy

    Upgraded internal database encryption with 256-bit peppered entropy and DPAPI-hardened key protection.

  • Advanced Auth Standards

    Migrated to PBKDF2 with 600,000 iterations and implemented O(1) constant-time API key validation to mitigate timing attacks.

  • Weighted Security Scoring

    Introduced a sophisticated 0-100 security scoring engine with structured risk tracking for unauthenticated services and remote exposure.

High-Velocity Discovery
  • 3.2x Port Scanning Concurrency

    Optimized socket hygiene and concurrency models to boost port enrichment speeds by over 300% on high-density networks.

  • Authoritative Subnet Verification

    Implemented full bitwise CIDR masking for all subnet sizes, ensuring 100% accuracy for massive /16 corporate environments.

  • Proactive ThreadPool Tuning

    Moved high-concurrency environment tuning to the host level to eliminate 'ramp-up' latency during initial network sweeps.

Modernized UX & Performance
  • Premium Header & Profile Experience

    Retired the legacy power icon for a modern User Avatar system with integrated profile management and alert diagnostics.

  • Reactive Progress & Pulse

    Converted the scan engine to a push-model reactive system for instantaneous, millisecond-accurate progress feedback in the UI.

  • Atomic Settings Architecture

    Standardized all settings layers to use high-performance atomic write patterns, eliminating I/O latency and disk corruption risks.

v1.2.4

Released April 19, 2026


Industrial Performance & Observability
  • High-Performance Negative Caching

    Smashed the 'Scan Stall' bug by implementing persistent negative caching for DNS and SNMP. Reduces sparse network scan times by up to 40%.

  • Reactive Engine Control

    Scan parameters now apply instantly via a CancellationToken interrupt system. Changes to subnets or intervals no longer wait for the engine sleep cycle.

  • Proactive ThreadPool Scaling

    Eliminated scan 'ramp-up' latency by scaling the .NET ThreadPool proactively to match configured parallelism, preventing thread starvation.

  • Industrial Log Viewer Terminal

    Introduced a high-performance terminal UI for real-time engine logs, featuring millisecond-accurate stage timing and severity filtering.

  • Logic: Removed Double Hysteresis

    Eliminated a hidden 5-strike grace period. The engine now respects your configured status thresholds immediately.

  • Logic: Relaxed Ghost Protection

    Docker/restricted devices responding only to ICMP now show as 'Online' with an 'Unknown MAC' instead of being rejected.

  • Observability: Detailed Rejection Logs

    The engine now explicitly logs which IPs were dropped by synthetic filters, providing full transparency into discovery outliers.

Premium Branding Ecosystem
  • 30+ Professional Vendor Icons

    Massive expansion of the visual registry including premium logos for Dell, Synology, Samsung, Sennheiser, Yamaha, and major Pro-AV brands.

  • Crestron Brand Identity Refresh

    Smashed the 'Ugly Logo' placeholder bug by replacing the legacy text with a professional, high-quality gradient wordmark.

  • Smart Vendor Resolution

    Refactored detection logic to handle substring matches and common vendor variations (e.g. HPE/Aruba) automatically.

Bug Fixes & Hardening
  • Industrial ARP Resilience (Cisco Fix)

    Optimized the discovery engine to support managed network hardware that prioritizes ICMP over ARP responses.

  • Fail-Fast Network Timeouts

    Reduced default discovery timeouts from 2s to 1s to ensure rapid failure detection on large subnets without impacting accuracy.

v1.2.3

Released April 18, 2026


Industrial Hardening & OpenAVC
  • Official OpenAVC Integration Plugin

    Released the first-party StacksAtlas bridge for the OpenAVC platform. Enables real-time 'Network Pulse' status cards on AV control surfaces.

  • Industrial ARP Resilience (Cisco Fix)

    Relaxed Ghost-Ping protection to allow devices that respond to ICMP but delay ARP requests (common in managed switch security profiles).

  • Zero-Trust Discovery (Ghost-Ping Fix)

    Hardened neighbor verification to require active ICMP/ARP verification for all passive neighbors, eliminating stale ARP 'ghost' entries.

  • Universal Status Promotion

    Running a Traceroute or Deep Scan now automatically promotes the target device to 'Online' status.

UI & Documentation Refinement
  • High-Performance Interactive Changelog

    Complete refactor of the release history UI with real-time search, collapsible entries, and optimized filtering logic.

  • Standardized Iconography System

    Unified industrial-grade icons across all historical release notes for consistent visual governance.

v1.2.2

Released April 13, 2026


Discovery & Scanning Resilience
  • Industrial Ghost-Ping Suppression

    Implemented a 'Physical Reality Check' for all scans. If a sweep returns suspiciously high counts (>85%), a mandatory triple-verification loop is triggered automatically.

  • Socket & Resource Awareness

    Nmap discovery now monitors OS network buffers for 'Resource temporarily unavailable' errors, aborting unreliable scans rather than reporting false data during system load.

  • Parallelism Jitter Optimization

    Added randomized micro-delays (0-20ms) to parallel pings to distribute peak network stack pressure and prevent packet reflections.

Appliance Deployment & Security
  • Dynamic Port & Restart Management

    Full UI-driven control over HTTP/HTTPS ports with a graceful, persistent restart-and-migrate workflow. No command-line access required.

  • Premium API Docs (Scalar)

    Replaced standard Swagger with a beautiful, high-performance Scalar UI at /api-docs. Securely gated behind Admin roles for internal development.

  • HTTPS Trust Maturity (CA Certs)

    Upgraded self-signed certificate generation with modern .NET 10 APIs and 'Basic Constraints: CA=True' to satisfy strict browser trust requirements.

  • Industry Standard API Keys

    Built a robust PBKDF2 hashed token system for external API access, replacing the legacy static JWT model with individually revocable keys and usage auditing.

  • Licensing Strategy Pivot

    Updated the engine to support our new commercial accessibility tiers: Free (50 devices) | Pro (100 devices) | Enterprise (Unlimited).

v1.2.1

Released April 5, 2026


macOS & Security Maturity
  • Native macOS Discovery Engine

    Implemented a passive 'Stage 0' discovery layer using netstat and arp for instantaneous device recognition on Darwin, bypassing traditional socket throttling.

  • RBAC & Security Hardening

    Refined Role-Based Access Control to allow 'Normal' users read-only access to Dashboards, Topology, and Alert History while strictly gating administrative settings.

  • Zero-Config Nmap Automation

    Automatic path resolution for Nmap on macOS (Homebrew or Bundle paths) with hardened privileged execution for OS fingerprinting.

Infrastructure & Automation
  • Professional Cloud Distribution (R2)

    Replaced manual fulfillment uploads with an automated Cloudflare R2 pipeline. All installers now support versioned permalinks.

  • Self-Hosted Windows Builder

    Integrated native Windows MSI generation with industrial code signing into the global CI/CD pipeline.

  • Master Build Orchestration

    New root-level automation script for 'One-Click' build, sign, distribute, and git-sync operations.

  • Universal Safe-Deployment Gates

    Implemented 'Neutral Skip' logic across all platforms (Windows, macOS, Linux/Docker) to prevent accidental public releases while keeping the CI dashboard green.

v1.2.0

Released March 28, 2026


Cross-Platform & Infrastructure
  • Native Docker & macOS Support

    StacksAtlas can now be deployed natively on Apple Silicon/Intel Macs and any Linux server (Ubuntu, Synology, Unraid) via Docker!

  • Nmap-Powered Discovery Engine

    Resolved the 'Ghost Ping' bug on Linux by pivoting to a native Nmap discovery backend, ensuring 100% accurate device counts in Docker.

  • Automated CI/CD Pipeline

    Implemented GitHub Actions to automatically build and publish Docker images and native macOS binaries on every release.

v1.1.0

Released March 1, 2026


Enterprise Discovery & Telemetry
  • Live Topology Visualizer

    A beautiful, interactive Canvas-based Force-Directed Graph mapping the entire scanned subnet in real-time.

  • SNMP Engine Integration

    Native SNMP v2c support for fetching System Name and Description from managed hardware (Switches, NAS, Routers).

  • Cross-Platform ARP Resolution

    Replaced legacy Windows PInvoke with a robust, cross-platform engine for universal networking compatibility.

  • Rapid7 Recog Device Fingerprinting

    Integrated Recog XML signature engine for industrial-grade hardware identification.

  • Racing Discovery (Performance Boost)

    Simultaneous ARP+Ping 'racing' logic reduces subnet sweep times by up to 30%.

Reliability & Robustness
  • Dynamic MAC Identification

    Fixed startup race conditions; auto-detection now handles late network interface initialization gracefully.

  • Setup Gate Optimization

    Scanning now starts instantly after creating the initial admin account—no restart required.

v1.0.6

Released February 16, 2026


Critical Fixes
  • Startup Hang (Hotfix)

    Fixed a critical race condition causing service hangs on startup. Startup is now sub-second.

  • Security Audit Sync

    Fixed race condition where acknowledged security risks were reverting.

  • Login & API Reliability

    Resolved a 'Invalid URL' crash in ApiService and a LiteDB mapping exception.

  • Filter Logic Bugs

    Fixed regressions in 'Show Archived' toggle and 'New' filter logic.

  • State Persistence

    Fixed issue where manual device edits were not persisting.

Improvements & Polish
  • Optimistic UI Updates

    Implemented immediate visual feedback for risk acknowledgement.

  • Protocol Quick Links

    Added one-click launch support for SSH, Telnet, and FTP.

  • Enhanced Security Reporting

    PDF/CSV reports now include Security Grades (A/C/F).

  • Permanent Delete

    Added 'Hard Delete' option for complete removal.

  • Natural IP Sorting

    Smart sorting for IP addresses in lists and reports.

  • Reset Metrics

    Manual reset capability for device performance counters.

v1.0.5

Released February 7, 2026


Core: The Physical Reality
  • Wake-on-LAN (WoL)

    'Magic Packet' support to boot up offline workstations remotely.

  • Path Diagnostics

    Visual Traceroute to identify latency bottlenecks.

Intelligence & Security
  • DHCP Lease Detective

    Historical tracking of MAC-to-IP bindings to spot 'drifting' devices.

  • Legacy Lifeboat

    Detection of EOL OS (XP/Win7) for immediate risk forecasting.

  • Enterprise Transparency

    Added dependency disclosure (Npcap/Nmap).

Under the Hood
  • Stability Core

    Fixed critical race conditions and deadlock prevention.

  • UI Polish

    Modernized scrollbars and layout refinements.

  • Sweep Optimization

    Cutdown sweep time from 30s to 5s.

v1.0.4

Released January 29, 2026


New Features
  • Network Intelligence (Deep Scan)

    Integrated Nmap scanning for deep service discovery.

  • Licensing Resilience

    Correctly activated licenses now support 30-day offline grace period.

  • Real-Time Progress

    New progress bar UI provides live feedback during deep scans.

  • Bundled Deep Scan Tools

    Installer now handles Nmap dependencies automatically.

  • Expanded Device Intelligence

    Native detection for IP Cameras, NDI Video, and Storage Infrastructure.

  • Startup Accelerator

    Splash screen and lock contention resolution.

  • Self-Healing Metrics

    Automated global repair of legacy stability data.

  • HTTP Title Intelligence

    Native fetching of web page titles for better ID.

  • PTP Master Detection

    Real-time identification of PTP Master clocks.

  • Database Portability

    Added secure encrypted database migration export.

v1.0.3

Released January 25, 2026


New Features
  • Deep Pro-AV Integration

    Enhanced classification for Dante, Q-SYS, Biamp, Shure, and Crestron.

  • Protected Manual Overrides

    Manual edits to Model or Vendor are protected from automated overwrites.

  • Expanded Device Icons

    Specific icons for Microphones, Amplifiers, Mixers, and NAS.

v1.0.2

Released January 20, 2026


Core Appliance Maturity
  • System Restart

    Added capability to restart the host service/system from the UI.

  • Network Control

    Added Network Adapter selection and transparency.

  • Data Sovereignty

    Added Backup & Restore (Snapshot) functionality.

  • Signed MSI Installer

    Ensuring secure and trusted deployments.

v1.0.0

Initial Public Release


The Birth of Intelligence
  • Core Discovery Engine

    Industrial-grade network scanning and identification.

  • Stability Scoring

    Weighted analytics for predicting hardware failure.

  • Reporting Engine

    Professional PDF and CSV exports for inventory audits.

Built by Keaton


© 2026 StacksAtlas LLC. All rights reserved.