Threat Model Reviewer

Changelog

Public repository documentation · View source on GitHub

This public changelog preserves historical entries and explicitly labelled unreleased notes. Unreleased items are not claims about the stable binary.

On this page

All notable changes to Threat Model Reviewer are documented here. The format is based on Keep a Changelog, and the project aims to follow Semantic Versioning.

[Unreleased]

No additional changes are queued here.

2.6.0 — 2026-09-14

Release qualification and packaging

  • Separate source/package versions from published metadata during release qualification; promote the public version only after publication.
  • Require current save/discard/cancel decisions before model replacement or window exit. Failed saves keep unsaved edits; late confirmations and original-file saves cannot overwrite newer in-memory work. Add a separate New window action.
  • Make update discovery product-specific and bounded across API pages. An unavailable or incomplete listing is not "up to date"; the public product snapshot can identify a newer stable release with actual assets, without guessing URLs from Atom tags.
  • Stage fresh desktop and CLI payloads with the same verified SDK-pinned runtime, stamp both executable versions, preserve signing/upgrade identities, and require the complete artifact set. Emit provenance and SHA-256 metadata.
  • Keep publication draft-only until promotion, without changing another product's global-latest status. Scope document exports to TMR, retain shared hub policies, and use product download routes in app, CLI and skill guidance.
  • Add counted packaging reports, explicit self-signed trust guidance and bounded Microsoft TMT compatibility documentation. Full native dashboard and disposable installer acceptance are distinct from parser/serializer or package preflight.

Diagram workspace

  • Wrap Diagram actions and separate manual selection/tools, Copilot proposal review and advisory chat. Keep proposal actions reachable while instructions, attachments, errors and review details scroll; preserve existing edit, save, reset and connect commands.
  • Add named zoom controls, keyboard element/flow-label movement, keyboard flow renaming, visible document focus and UIA selection state. Expose full labels and stencil details without resizing or rerouting the model for appearance.
  • Keep the document light in both themes, including unknown shapes and inline name editing; retain installed stencil matching and vector fallback for shared previews.
  • Clarify image-pixel privacy and human review: model edits are not code or deployment remediation. Model-revision protection is covered separately below; native TMT UI isolation and universal accessibility conformance are not claimed.

Overview, Findings and Fix review interface

  • Separate readiness-gate explanations from maturity scoring without assuming that every model is thorough or approved. Keep overview coverage statuses readable without colour alone.
  • Add labelled finding search, severity/gating filters and visible/total counts. Keep sorting and row virtualization, compact long titles/targets, and full selected-finding details. Filters do not change the engine findings, exports or bulk operations.
  • Compact Fix actions, name inclusion checkboxes, show source/selection summaries, and provide a selectable read-only exact-content preview. Refresh that preview when replacing an active draft, clear detached row selection when rebuilding a plan, and keep built-in placeholder warnings when switching back from an AI draft.
  • Identify producing providers and offline placeholders in review guidance and fix drafts; expose bounded progress/error text and tab-local keyboard focus and semantic-colour styles. Preserve the shared shell, Create/Assistant layout, rubric and model-write semantics.

Desktop shell accessibility

  • Separate loaded-model context from wrapping header commands so Help, Provider and the AI model picker remain available at the minimum window width. Give Ask real footer space and keep its panel within the workspace height.
  • Gate tab accelerators on the same availability as mouse navigation; retain Ctrl+1…7, add Ctrl+8/9 for Create/Assistant, and support Ctrl+Tab and F6 shell navigation. Manage Ask focus consistently for mouse and keyboard, with Escape dismissal and return focus, while preserving the shared conversation.
  • Add native labels for shell inputs, icon actions and provider choices; distinguish selected, disabled and keyboard-focused shared controls. Use contrast-safe brand fills for white labels in dark-theme active states and avoid doubled field padding. Keep the semantic hover/pressed fill aliases contrast-safe for tab-local templates too.
  • Make rendered Markdown code highlights and quoted caveats follow live theme resources, including already displayed answers, without rebuilding their text.
  • Preserve the existing Segoe UI, themes, authoring-only styles, independent authoring draft, source labels and comparison provenance. These are bounded desktop checks, not a blanket accessibility-conformance claim.

Diagram model-revision safety

  • Separately bind Diagram proposals to captured model/editor identities, surface and the existing edit/reparse sequence. Reject stale preview/apply even when an A response arrives after B was loaded, or an already-previewed plan outlives its document.
  • Cancel and explicitly discard obsolete Diagram work on model/request transitions. Late success, failure and progress cannot overwrite a newer operation's busy/error state or consume its input. Discard model-bound Diagram chat answers/citations on replacement and structural changes.
  • Apply reviewed changes on a detached editor, then validate ownership before publishing. Guard delayed Diagram save/reset/reparse publication with the existing sequence. Preserve normal apply/save behavior; do not alter provider/MCP internals or the rubric.
  • Invalidate prepared state and busy/history ownership before invoking cancellation callbacks. A throwing callback cannot abort load, close or shutdown; report a generic callback-failure/discard notice without exposing provider exception text.

Review advisory revision safety

  • Tie finding explanations, deep analysis, critique, framework-gap and interaction guidance, and fix drafts to their captured model/review and the existing structural-refresh sequence. Cancel local waits and reject obsolete completions, progress and errors without a second document-version counter or changes to provider/MCP sessions.
  • Preserve row-selection independence and balanced busy accounting; old request cleanup cannot clear a newer request's flags. Invalidate completed advisory content and fix plans on re-review, and prevent old drafts from matching regenerated plan rows through reused action IDs.
  • Keep reset, plan replacement and final shutdown progressing even if a provider's cancellation callback throws; report only the callback-error count, not request or response content.
  • Guard bulk/upload review and AI-export orchestration as well as individual requests. Abort obsolete export choices, and do not export an in-flight analysis placeholder as completed content. Keep deterministic review output and the current tab layout unchanged.
  • Guard overlapping file loads with the existing refresh sequence and return the exact adopted review identity. Recheck it before navigation, optional AI or post-save status. Fix writes retain their original model/plan, reject stale re-entry before resetting/loading, and cannot clear a newer load's busy state. An already-started original-file write is not rolled back; the unchanged valid path still uses the existing parser, rubric and .tm7 writer.

Compare, Ask and History

  • Keep Compare inputs and immutable saved-byte results in one scroll area; expose selectable path/hash/options provenance, matching limitations and cancellation. Preserve snapshot invalidation, literal exports and unchanged deterministic scoring.
  • Keep the Ask tab and floating panel on their existing shared conversation/provider path. Add consistent Automatic (local-first), Local only and explicit selected-AI advisory modes, readable source labels, cancellation, clear-chat and explicit retry. Disconnected or failed local summaries are never presented as Copilot answers.
  • Bind Ask turns and verified references to their originating model/review. Reload, replacement, review changes, close and shutdown discard obsolete work, even when providers ignore cancellation. Hiding or opening the panel in the tab preserves its conversation and draft. Keep prompts/responses out of production history/logs.
  • Make History's privacy/export controls reachable, show actual retention settings and improve wrapped activity rows. Check stored as well as located file paths against recorded content hashes; never infer revision identity from filenames.
  • Verify with counted/delayed/failing fake providers and synthetic models. Live Copilot sign-in/inference and MCP service acceptance are not claimed.
  • Label verification hosts explicitly Offline/fake, isolate their profile and history, and guard non-activating HWND-specific checks and unchanged-state cleanup. These checks do not replace physical-keyboard or foreground-focus acceptance and never use a user's normal app as the verification target.

Create and Assistant authoring

  • Reorganize Create around source choice, labelled editable rows, inspectable validation and metadata, and a generation/evidence command bar that stays visible. Collapse optional refinement, diagram preview and baseline detail instead of putting them ahead of editing.
  • Separate Assistant description, document and image selection from explicit extraction and the Create review/generation handoff. Stage images locally, disclose image privacy and document truncation, and reuse global model/MCP settings without enabling connections.
  • Add cancellation, useful empty/disabled/retry states, selectable wrapping errors and keyboard focus for authoring controls. Supply the missing editable ComboBox text part using an authoring-only style; keep the existing Segoe UI, Fluent tokens and themes.
  • Reject obsolete extraction responses after input/draft changes, preserve drafts on empty provider output, and protect refinements during provider acquisition as well as completion. Keep follow-up instructions typed while waiting. Inspect all import notes and effective metadata without changing generation, evidence ownership or deterministic scoring contracts.

Generation integrity

  • Generate the desktop model, status and evidence from the same pipeline result, including the baseline-carried path, instead of writing a separate model.
  • Preserve imported metadata and stable identities through draft edits; invalidate interaction-specific assertions when endpoints change.
  • Separate Azure observations from the edited draft in evidence, reject stale refinement responses, and recover from ordinary artifact-publication failures.
  • Bind desktop sidecar replacement to model.tm7.generation.json ownership and exact model/sidecar hashes; preserve edited, legacy and unowned evidence on conflict.
  • Retain declared HTTP signals and native-compatible connector properties through both writers. Preserve references during temporary blank/duplicate renames and reject ambiguous identity reuse during refinement.
  • Verify synthetic rich, Azure-derived and neutral-HTTP fixtures against the installed Microsoft TMT 7.3.51110.1 serializer through read/save/reload. Full native dashboard/UI acceptance remains a separate, uncompleted isolated-environment requirement.

Optional MCP developer context

  • Add default-off, explicit-tool Learn, pinned Azure metadata and read-only GitHub profiles. GitHub context uses its own repository-scoped, DPAPI-protected credential.
  • Add app and CLI consent/configuration/credential controls, explicit connection testing and per-AI-request --mcp opt-in; normal review and factual ask stay offline.
  • Disable SDK ambient context sources explicitly, wait for actual connection state, and bound shutdown with force-stop escalation and explicit cleanup errors.
  • Keep Azure DevOps MCP deferred until its authentication is supported.

Azure discovery, comparison and handoff

  • Run the direct Azure reader without a command shell, using fixed native Python/CLI arguments and Windows process containment. Carry the captured subscription from the picker through discovery; malformed output and failed cleanup are not successes.
  • Capture immutable desktop comparison revisions/options, invalidate stale operations and export dialogs, disclose ambiguous threat matching and bounded heuristic passes, and keep model-provided Markdown/CSV values literal.
  • Capture CLI SDL source bytes once for parsing and provenance. Validate identifiers before output; disclose unknown states and AI blocks; publish the manifest last. Bundle replacement is not transactional or power-loss atomic.

Documentation and website

  • Clarify that model fixes do not patch application code, and a readiness result is not Microsoft approval or proof that mitigations are implemented.
  • Add a public synthetic sample and quick-start workflow tied to the actual rubric output.
  • Add an explicit public-document map, link-aware synchronization command and read-only drift check; record the cross-repository documentation workflow.
  • Correct stale public Create/Assistant descriptions and privacy/network guidance for Azure, MCP, document extraction and image input.
  • Replace the manually maintained source test-count badge with the CI status badge.
  • Keep CI test-report artifacts for failed runs only, with seven-day retention; successful build/test results remain in the run logs.
  • Align the shared app/CLI/privacy/enterprise and skill guides with development-only behavior. Add a publication-channel guard so local previews cannot silently replace stable guides. Preserve the published release history and downloads.
  • Correct managed uninstall examples to use the deployed MSI/ProductCode, not UpgradeCode, and distinguish signed binaries from ZIP and skill containers.

Release safeguards

  • Await every owned request during Azure cancellation-test teardown, even when another cancellation assertion fails; directory removal must not hide the original failure by abandoning a still-cleaning-up request.
  • Default the build version from the app project and reject mismatched versions, unsupported runtime targets and mismatched supplied Copilot runtime metadata.
  • Use unique staging directories and verify copied app/CLI runtime hashes against the explicitly supplied bytes. A side-effect-free -PreflightOnly check reports PackagingVerified: false; it does not certify installer or runtime acceptance.

Fixed in source, not yet included in a new binary release

  • Widen the Findings check column and use an ellipsis plus tooltip for long targets.

2.5.1 — 2026-09-07

Three defects found by looking at what the product actually renders, rather than at what the code says it renders.

Fixed

  • Azure components were labelled "Generic Process" on the diagram. StencilCatalog.FriendlyName consulted an element's generic stencil family before deriving a name from its specific stencil id, so any product not in the curated table lost to its parent — an Azure Logic App read as "Generic Process" while the .tm7 underneath correctly said SE.P.TMCore.AzureLogicApp. Spotted on three components; a guard covering every stencil the Azure map can emit measured the real scope at 79 of 92. The model was right and only the label was wrong, which is the worst combination because nothing looks broken.
  • Flow labels could be hidden by a component. Labels were painted as part of the connector, and connectors are painted behind the nodes so a line reads as passing under a box rather than terminating at it. A label that happened to sit where the layout placed a node was clipped to a single character, so the diagram silently stopped saying what the flow carried. Labels are now painted last, and a test asserts the layering.

Added

  • A framework-edition manifest, and a drift guard that holds it to the code. Which edition of each standard the tool encodes was folklore spread across a knowledge base, a coverage matrix and several rule tables. It is now declared once and checked, because a manifest nothing verifies is just another thing that goes stale.
  • Reports state which editions produced the verdict, and disclose anywhere the tool is knowingly an edition behind, with the reason. Being behind is sometimes right; being quietly behind is not, so the manifest refuses to record an unadopted edition without a stated reason.

Framework currency (verified against each publisher)

  • OWASP Top 10:2025 — current. All ten shipped citation URLs verified live.
  • OWASP API Security Top 10:2023 — still current.
  • CWE — individual identifiers are stable and edition-independent; the annual Top 25 ranking is not encoded, so it cannot drift.
  • OWASP Top 10 for LLM Applications — the tool encodes 2025; edition 2026 was published on 3 August 2026 and is deliberately not yet adopted. It re-ranks eight of the ten risks (Excessive Agency LLM06→LLM03, Improper Output Handling LLM05→LLM10, and six more), so adopting it means remapping identifiers rather than changing a year. OWASP has not published per-risk pages for 2026 — its own index still links every risk to the 2025 pages — so renumbering now would leave every citation pointing at a page whose identifier no longer matches its title. This is disclosed in every HTML and Markdown report rather than left in a comment.

2.5.0 — 2026-09-07

Threat models are built from what a team wrote down: a diagram someone drew, or infrastructure code that describes what was declared. Neither is the same as what is running now. This release reads the deployed system instead.

Added

  • Build from a deployed Azure resource group. In the app, Create → Build from Azure…; in the CLI, azure <resource-group> --out spec.json --evidence. Reads what is actually deployed and drafts a threat model from it. Deterministic and AI-free: the same resource group always produces the same model.
  • Data flows inferred from role assignments. A managed identity holding a data-plane role on a store is evidence that the resource holding that identity reads or writes it — a path that exists in production whether or not anyone drew it. Roles that only grant control over configuration (Contributor, Reader, Owner) are deliberately not drawn, and neither are subscription- or management-group-scoped grants: measured on a real resource group, 111 of 115 assignments were inherited governance rather than one component talking to another.
  • An evidence file for every Azure build. Records the subscription and group, every command run, which flow came from which role assignment, every resource left off the diagram and why, the configuration observed, and what discovery could not read at all.
  • Discovery's limits are written into the model as assumptions, not left in a side file — so the .tm7 cannot travel on its own looking more certain than it is. Chief among them: access using a shared key leaves no role assignment, so it is invisible here and missing from the diagram.
  • Azure resource types become TMT stencils, so product-specific threat rules fire — a Key Vault gets Key Vault threats rather than generic data-store ones.

Security

  • Read-only by construction, not by convention. No caller can hand the Azure wrapper a command string at all: every read is a named method building its own arguments, re-validated against an allowlist before execution. Nothing can create, change or delete a resource, and no command that reads a key, secret or connection string is reachable. A test asserts the guarantee by reflection, so adding a method that accepts a caller-supplied command fails the build.

Changed

  • Resources are now included on a discovered diagram only when their type is recognised, rather than excluded when they match a list of known plumbing. Azure has hundreds of resource types and gains more constantly; the old shape put every unfamiliar type on the diagram as a process box. On a real resource group this cut the draft from 23 components — 20 of them unconnected noise — to 7 real ones. Everything excluded is listed in the evidence file with the reason.

Fixed

  • Two resources sharing one user-assigned managed identity no longer crash evidence generation. Shared identities are ordinary Azure configuration; the code treated a duplicate as a fault.
  • Resource-group lists in the Azure dialog now report a readable name to screen readers instead of the underlying record's raw text.

2.4.0 — 2026-09-06

Two engines that shipped in every build but could not be reached are now connected, and the guard that should have noticed no longer depends on anyone remembering.

Added

  • Assistant data sources (MCP). Help → Assistant data sources lets the assistant check a model's assumptions against systems you already have access to — including the Azure MCP Server, which reads the subscriptions and resource configuration you can read, using your existing az login. Off behind two switches, and each source states what it can reach before you enable it. It never touches the verdict or the score.
  • Import architecture into the Create tab. Build a draft from what your team already has: Bicep, an ARM template, Terraform, or a draw.io / Excalidraw / Graphviz / Mermaid / Visio diagram. The reading is deterministic and shared with the CLI's ingest verb, so the two surfaces cannot disagree about what a file contains.

Fixed

  • The MCP subsystem was unreachable. Runtime, connection manager, config store and the Azure descriptor — with 43 passing security tests — shipped for several releases while CopilotProvider created sessions without ever populating SessionConfig.McpServers. It compiled, it was correct, and it did nothing.
  • The ingest engines were CLI-only. Bicep, ARM, Terraform and six diagram parsers were in every build, and the desktop app could not open any of them.
  • The importer threw on a file with no diagram in it, where it should return "nothing found". Found by a test written against its own documented contract.

Internal

  • OrphanedCodeTests replaces an allowlist with a structural check. FeatureWiringTests guards a hand-written list of capabilities, which only catches what someone remembered to add — which is exactly why MCP hid. The new guard flags any public engine that only the tests can reach and requires each exemption to carry a written reason. Verified by planting a deliberate orphan and confirming the build fails.
  • Surface parity now covers architecture import, so it cannot become CLI-only again.

2.3.0 — 2026-09-06

The tool is now usable from an AI agent, not only by a human at a keyboard.

Added

  • A GitHub Copilot CLI skill, shipped as ThreatModelReviewer-vX.Y.Z-skill.zip. It teaches an agent five jobs — review a model, explain why it is NOT READY, fix what is mechanically fixable, compare two revisions for regression, and generate a model with an evidence file — each mapped to what a developer actually asks rather than to our verb names. It carries the CI recipes, both spec schemas, and the full rubric so an agent can explain a check id instead of inventing one. See docs/SKILL.md.
  • The determinism invariant is stated in the skill in the imperative: never report a verdict you did not read out of the tool, never imply that any AI can change one, and stop rather than guess if the engine cannot be run. The verdict and the 0-100 score still come from 72 rubric checks with no AI involvement.
  • Invoke-ThreatModelReviewer.ps1 in the bundle finds the CLI — THREAT_MODEL_REVIEWER_CLI, then PATH, then the usual install locations — and forwards its exit code verbatim, since a wrapper that rewrote it would turn a failing CI gate into a passing one.
  • skill.zip is now built by scripts/build-release.ps1 and published with every release, with the version stamped into the plugin manifest and the bundle README so a forgotten bump cannot ship instructions that name a file that does not exist.

Internal

  • SkillPackagingTests, 23 tests. Nothing compiles a skill, so a wrong sentence in one becomes a wrong command. They assert every verb and flag the skill uses is one the CLI parses, that both documented spec examples deserialize and generate a real model, that every gating check is named in the rubric reference, that every relative link resolves, that the description stays inside the Copilot CLI's 1024-character limit, and that the release script still packages the bundle. Each guard was verified by breaking the thing it protects and confirming the test failed.
  • The surface parity guard now covers three front ends: a shared capability must be reachable from the desktop app, the CLI and the skill.

2.2.0 — 2026-08-27

Generated models can now be audited rather than trusted.

Added

  • Evidence files. Generating a model can write a .evidence.md beside the .tm7 recording the declared inputs, the resulting model, every rule that fired and how often, anything the generator synthesized on your behalf, and every warning it raised. Deterministic and AI-free: the same specification reproduces it byte for byte, so a difference means the input changed rather than the model drifting. --evidence in the CLI, a Write evidence file checkbox in the Create tab.
  • CI on every push and pull request (.github/workflows/ci.yml), building with -warnaserror. Until now the only workflow was release, triggered solely by a version tag — so nothing validated a pull request, and three Dependabot bumps (two of them major) sat with no checks at all.
  • Branch safety. The public release hub is protected server-side against force-pushes and branch deletion, verified by attempting one as the owner and having it rejected. The private source repo cannot use GitHub protection on this plan, so it has a committed pre-push hook (pwsh scripts/install-hooks.ps1) that refuses to force-push or delete main and runs build and tests first.

Changed

  • Dependencies: xunit.runner.visualstudio 3.1.4 → 4.0.0, Microsoft.OpenApi.Readers 1.6.22 → 1.6.31, actions/upload-artifact v4 → v7. Each was tested locally before merging, including the openapi verb specifically, since it consumes the bumped reader.

Internal

  • A surface parity guard asserts the desktop app and the CLI cannot diverge: a capability added to one must be reachable from the other. This is the defect class that once shipped the Create and Assistant tabs hidden while the CLI could already do the work.

2.1.9 — 2026-08-24

The CLI is now visible everywhere it should be, and two flaky tests are gone.

Fixed

  • The CLI was invisible on the website. Both the product page and the releases page map asset names to download cards, and neither knew about cli-win-x64.zip — so every release silently dropped it from the download grid. Both now show it, with its size and a link to the CLI guide.
  • The product page called the portable ZIP "Recommended" while the README, the install guide, the release notes and the releases page all said the MSI. The MSI now leads the download grid, carries the recommendation, and is what the hero button offers.
  • Package tables omitted the CLI. The install guide, the README artifact table and the enterprise deployment guide each enumerate the downloads; none listed the command-line bundle.
  • Two flaky tests. The Markdown renderer's STA helper swallowed a thread-join timeout and then asserted on an empty string, so it passed alone and failed under load with a misleading message. The streaming-progress test polled for a Progress<T> callback that xUnit marshals onto the same single-threaded context the polling loop occupied, so the two starved each other; it now records progress synchronously, which is what the provider's contract actually promises. Five consecutive full runs, no failures.

Internal

  • A guard asserts that any document listing the download packages lists the CLI bundle too.

2.1.8 — 2026-08-24

Both the desktop app and the CLI ship — and a regression that would have replaced one with the other.

Fixed

  • The in-app updater could have installed the CLI over the desktop app. Adding the CLI bundle in 2.1.7 gave a release two .zip assets, and the portable channel matched on the extension alone — so a portable desktop install was offered the command-line bundle. It now requires a portable archive, and a test asserts that no channel can ever deliver the CLI as an app update.
  • Copilot answers showed raw ## and > markers. The Markdown renderer handled inline formatting only, so headings and blockquotes — which Copilot uses to structure answers and to flag grounding corrections — arrived with their syntax visible. Headings, blockquotes and numbered lists now render, and #1234 or #FF0000 are still left alone.

Note on packaging

Every release contains both products, and will continue to:

Artifact What it is
…-x64.msi Desktop app installer (recommended)
…-setup.exe Desktop app installer (Inno)
…-win-x64-portable.zip Desktop app, no installation
…-cli-win-x64.zip Command line, for CI and scripting

2.1.7 — 2026-08-24

The command-line interface is now something you can actually download.

Added

  • ThreatModelReviewer-vX.Y.Z-cli-win-x64.zip ships with every release. The documentation had described CLI usage since 2.0, but no release ever contained a CLI — the only way to obtain one was to build the source, and the source repository is private. A reviewer following the docs reached a dead end. The bundle is self-contained and signed like every other artifact.
  • docs/CLI.md — download, exit codes, every verb, authentication, and a working GitHub Actions example that gates a build on the verdict and uploads SARIF.

Fixed

  • Every documented CLI command required the private repository. All seventeen examples used dotnet run --project ThreatModelReviewer.Cli, which nobody outside the repo can run. They now use the shipped executable.
  • "Threats by interaction" stopped short of the panel edge, leaving a large empty area beside it once the framework table below started using the full width. Both now share one rhythm.

Internal

  • Two guards: every artifact the documentation tells people to download must be produced by the release script, and the public CLI documentation may not instruct readers to build from source.

2.1.6 — 2026-08-24

Layout and labelling fixes across the Overview and Fix tabs, and a regression from 2.1.5.

Fixed

  • The Review options model picker showed raw records (AiModel { Id = …, Name = … }). A regression from 2.1.5: removing the shared ComboBox style's blanket item template fixed four blank dropdowns but broke this one, which had been relying on it. The guard added at the time only read MainWindow.xaml, so it did not see the dialog; it now reads every view.
  • Framework coverage stacked OWASP and STRIDE vertically, using half a wide panel and leaving the rest empty. They now sit side by side.
  • Unlabelled grid columns. The Fix tab's review column and the History tab's reopen column had blank headers; both are named. The Apply and Check headers were also too narrow and clipped.

2.1.5 — 2026-08-24

A crash on the Findings tab, four dropdowns that rendered blank, and README badges that had gone stale.

Fixed

  • The Findings tab threw and failed to render. Moving view models from literal colours to semantic tokens in 2.1.4 updated one colour converter and left the other parsing its argument as a colour, so drawing a severity threw FormatException ("Token is not valid"). Both converters now share one resolver.
  • Four dropdowns rendered as blank rows — the component and element-kind pickers on Create and Diagram. The shared ComboBox style imposed {Binding Name} on every ComboBox in the app, and a plain string has no Name. Lists of records now name their own display property.
  • The diagram-surface picker needed a display property after all, and its record calls it Label. Fixed while verifying the change above.
  • README badges claimed v2.1.2 and 418 passing while the app shipped 2.1.4 with 1297 tests.

Internal

  • Binding failures are now observable in development. WPF logs a broken binding and renders nothing, so the symptom is a blank column and no error — which is how the ComboBox defect survived several releases. Debug builds write those failures to a file, and an automated pass over all nine tabs reads it. Release builds are unchanged.
  • New guards, each verified against the real defect: the converters are exercised with the exact values the view models emit; every ComboBox must be able to display its items, checked by reflecting the collection's element type; the shared style may not impose a display binding; and the README badges must track the shipped version and the test count.

2.1.4 — 2026-08-24

Dark mode finished properly, keyboard shortcuts, and a history you can act on.

Added

  • Keyboard shortcuts — 16 accelerators for opening, closing, exporting, critiquing and moving between tabs, plus Ctrl + mouse wheel to zoom the diagram. Help → Keyboard shortcuts (F1) lists them; the list is checked against the window's real bindings in both directions.
  • Reopen from History. A row can now be opened again. File paths are not stored by default, so the app usually asks where the file is — and then uses the recorded content hash to tell you whether it is the same revision that was reviewed.
  • "What you did" in History — opens, exports, fixes applied and Copilot actions per model.

Fixed

  • Dark mode reached only part of the app. The guard added in 2.1.3 checked a single file, so 84 hard-coded colours survived across the dialogs and the diagram; the whole Diagram tab stayed light inside a dark window. Every view is now covered.
  • The diagram is a document, not chrome. Theming its shapes made every node a dark block with unreadable text. The canvas is now a light sheet inside a dark frame, with its colours pinned.
  • Icons that looked broken. The Threat Modeling Tool substitutes an 18×18 generic outline for elements left as a plain External Interactor or Data Store, which reads as a missing image when scaled. Those, and the legacy 16×16 glyphs, now fall back to our own name-derived icons — a chart for Power BI datasets, a file box for SharePoint. Real product artwork is unchanged.
  • "Threats by interaction" and "Framework coverage" were unusable on a wide monitor. Both had an unbounded column, so the name sat at one edge and the numbers at the other. Both are now capped.
  • Element names containing line breaks turned a single interaction into three ragged lines.
  • F1 did nothing — WPF's built-in help command claims it before window bindings see it.

Internal

  • Export, fix and Copilot events were recordable but never recorded; Copilot events could not even be attributed to a model. Both are now wired, so history describes work rather than just file opens.

2.1.3 — 2026-08-24

Appearance and reach: the app can now be themed, questions can be asked without leaving the tab you're on, and comparing two revisions is legible.

Added

  • Light, Dark and Match Windows themes (Help → Appearance). The choice is remembered, applies immediately without a restart, and System follows Windows as it changes.
  • A floating Ask panel. A launcher in the bottom-left opens a compact chat over any tab, so a question no longer costs you your place. It is the same conversation as the Ask tab: maximising hands the history over rather than starting again.
  • "Use open model" on both Compare fields, plus a swap button. Comparing the open model against an older revision is as common as the reverse, and only the baseline supported it.

Changed

  • The Compare tab leads with the verdict and separates what got worse from what got better, instead of stacking dense lists of long strings.
  • Overview statistics sit on an even four-column grid; eight tiles previously broke 5 + 3 and left a gap.

Fixed

  • Interactions without a name printed their endpoints twice in "Threats by interaction".
  • Closing a model now dismisses the floating Ask panel, which otherwise stayed open over the empty state with nothing left to answer about.

Internal

  • Every colour in the app now resolves through a semantic token — 114 hard-coded values in the main window, 26 white backgrounds across the dialogs, and 43 literals chosen in view models. Guards were added for each way this fails quietly: the two palettes must define the same tokens and differ on the core surfaces, no themed brush may be bound with StaticResource (which resolves once and then ignores a theme change), and no colour may be hard-coded. The diagram is exempt by design: it renders a document, not app chrome.

2.1.2 — 2026-08-23

Fixes found by driving the app before shipping rather than trusting a green test suite.

Fixed

  • The History tab was empty even after a review. Two separate faults. The recorder was never called — the store, query layer, privacy controls and tab were all complete and all tested, and nothing invoked them, so the feature did nothing while every test passed. And once recording worked, the tab still showed nothing until you noticed the Refresh button. Reviewing a model now records it, and opening the tab loads it.
  • The assistant showed its own Markdown. Answers are written in Markdown and were bound straight to text, so readers saw **NOT READY** and literal dashes — the most important line in an answer was the hardest to read. It now uses the renderer the app already had.
  • The test suite wrote into the real history store. Wiring the recorder into model loading meant any test that opened a model recorded a review, filling a developer's History tab with fixtures. The history root now honours THREATMODELREVIEWER_HISTORY_ROOT, which the tests redirect to a temp folder — and which administrators can use to move history off a roaming profile.
  • Compare's Explain and Export buttons looked broken. They are correctly disabled until a comparison exists, but said nothing; they now explain themselves while disabled. The path boxes also accept a dropped .tm7.
  • A documented claim was untrue. The docs said generate produces a NOT READY model "by construction". It does not: a generated model reports READY WITH NOTES with zero gating findings, because the rubric counts Needs Investigation as triaged. The docs now describe what actually happens, and why a generated model still is not a reviewed one.
  • The framework coverage matrix was labelled "OWASP Top 10 (2021)" while listing the 2025 categories updated in 2.1.1.

Added

  • Feature wiring tests. The History bug could not be caught by unit tests — every part passed in isolation; the gap was between the code existing and the code running. These assert that each capability is reachable from a surface a user can drive: every Core engine referenced by the app or CLI, every advertised tab present and not collapsed, every CLI verb dispatchable, the recorder actually invoked, and the assistant rendering Markdown. They cannot prove a feature is correct, only that it is not orphaned.

Notes

  • The verdict and 0–100 review score remain 100% deterministic; Copilot stays advisory.
  • 1231 automated tests.

2.1.1 — 2026-08-23

A follow-up to 2.1.0 fixing three things that stopped users seeing any of it, plus a correction to the standards the rubric cites.

Fixed

  • In-app update could produce an unusable installer. Downloads were only size-checked when a length was known. On the release-atom fallback — taken whenever the anonymous GitHub API is rate-limited at 60 requests an hour — every asset size is reported as 0, so if the server also omitted Content-Length nothing was verified at all. A truncated transfer or an error page was moved into place and handed to msiexec, which reported "This installation package could not be opened" — an error that says nothing about the download. Every download is now format-checked before it runs (an MSI must start with the OLE compound-file signature, a zip with PK, an executable with MZ) and the failure names the real cause. The published 2.1.0 MSI was never faulty; only the download path was.
  • The header could collapse and hide the tab strip. The identity block sat in a star-width column beside a content-sized command cluster. Adding the Close button in 2.1.0 tipped it over: the cluster claimed the row, the star column collapsed to a few pixels, and the title wrapped one character per line down the left edge, pushing the tabs off screen. Rebuilt as a single compact strip — roughly 50px — in which nothing can wrap; the open model's name trims with an ellipsis.
  • The verdict was printed twice. The CI band is FAIL precisely when the verdict is NOT READY, so showing them as separate chips read as two independent failures, and previously put a green grade pill beside a red FAIL. They are now one chip.
  • Markdown was rejected as "not a diagram". .md is registered as a diagram extension because markdown can embed Mermaid, so plain prose never reached the document reader. Shared extensions now fall back correctly, and markdown containing a diagram is still read as one.

Changed

  • Compare, Ask and History are now in the app, not just the CLI. 2.1.0 shipped these engines with no way to reach them outside a terminal.
    • Compare — pick two revisions (or use the model you already have open as the baseline) and see what changed, what got worse, and what got better, with the score and verdict movement. Explain with Copilot adds a plain-English read of the change; the numbers are computed before Copilot is asked and never change. Exports to HTML, Markdown or CSV.
    • Ask — an assistant scoped to the open threat model. Common questions are answered straight from the model's own numbers with no AI call at all, so no answer can contradict the review; each reply says which of the two it was. Open-ended questions go to Copilot grounded in the same facts, with the supporting check ids cited.
    • History — every review you run, recorded locally, with score trends per model. The tab states where the data lives and can open that folder, because "it never leaves your machine" is a claim you should be able to verify rather than take on trust. One click clears it.
  • Create and Assistant are no longer hidden. Both were fully implemented behind Visibility="Collapsed", and with 2.1.0 shipping a round-trip-verified .tm7 writer there is no longer a reason to keep model authoring out of the product. Create offers templates, Copilot refinement, a live diagram preview, components, flows and boundaries; Assistant extracts a DFD from a document, an architecture image, or an OpenAPI spec.
  • The app and the CLI now run the same generation engine. The Create tab used the original generator while generate used the deterministic pipeline. Two implementations of one feature drift, and a user comparing them would rightly lose confidence in both. Create now reports how many threats it produced and states that each is recorded as Needs Investigation, so its output is not mistaken for a finished review.
  • Rubric citations updated to OWASP Top 10:2025, published 6 November 2025. The edition re-ranked categories rather than just renaming them, so all 43 references were mapped by concept: Cryptographic Failures moved A02→A04, Injection A03→A05, Insecure Design A04→A06, Security Misconfiguration A05→A02, and Vulnerable & Outdated Components (A06) became Software Supply Chain Failures (A03). SSRF is no longer its own category — OWASP folded it into A01 — and A10 is now Mishandling of Exceptional Conditions. No score changes: the coverage matrix feeds reports and the assistant, never the engine, and both sample models score exactly as before.
  • Release builds now upload their artifacts before publishing, so a missing or expired publishing token costs a manual publish rather than a repeated build.

Notes

  • The verdict and 0–100 review score remain 100% deterministic; Copilot stays advisory.
  • 1200 automated tests (up from 418 at the start of the 2.1 cycle).

2.1.0 — 2026-08-23

This release is mostly new engine capability, reachable from the CLI. The desktop UI for these features lands next; everything below is available today via ThreatModelReviewer.Cli.

The verdict and 0–100 review score remain 100% deterministic. Copilot stays advisory, and several of the additions below exist specifically to keep it that way — the assistant answers from computed facts rather than inference, and generation lets a language model touch prose only, never structure.

Added

  • compare — what changed between two revisions. Matches elements, flows, boundaries and threats by stable identity rather than list position, so a rename is reported as a rename instead of a delete plus an add. Reports rubric deltas including pass→fail transitions, threat state changes, and a posture summary that makes regressions impossible to miss. Exits 2 on a serious regression so CI can block on it.
  • generate — build a .tm7 from a described system. Deterministic STRIDE enumeration keyed on element kinds, boundary crossings and flow properties. Every generated threat is recorded as Needs Investigation: this is an enumerated starting point, not a completed review, and the output says so. Generating twice from one spec produces byte-identical output.
  • ingest — read what teams already have. Documents (Word, PowerPoint, Excel, PDF, CSV, Markdown, JSON, YAML), diagrams (Excalidraw, draw.io including its compressed form, Mermaid, Visio, Graphviz), and infrastructure as code (ARM, Bicep, Terraform). Diagrams are mapped to data-flow-diagram candidates; anything the mapper cannot classify confidently is flagged for a human rather than guessed at. Infrastructure ingestion extracts deterministic security facts — TLS enforcement, public network access, identity type, key-vault protection, firewall rules — each with a file and line citation, and exits 2 when it finds insecure configuration.
  • sdl — the artifacts a reviewer actually asks for. A full threat model document (Markdown and HTML), the threat register (CSV and JSON), an assumptions and out-of-scope log, a traceability matrix, and a manifest recording tool version, rubric version and the source model's identity and hash, so a reviewer can verify every file and reproduce the deterministic content.
  • ask — answers with no AI and no network. Common questions (score, verdict, unmitigated counts, which flows cross a boundary, why a model is not ready) are answered exactly from a computed fact sheet, with the supporting check ids cited. Questions needing judgement are declined rather than guessed at.
  • policy — organisation policy, with disclosure that cannot be switched off. Validate a policy, list the check ids one may reference, or apply one to a review. Waivers require a reason, an owner and an expiry; an expired waiver stops applying and becomes a finding of its own. Applying a policy always prints the unpoliced result beside the policed one, plus every suppression and the policy's hash — a policy can tune the rubric, but it can never quietly hide a failure. Ships default, strict and a worked enterprise-exceptions preset.
  • history — local review history and score trends. Append-only, on this machine only, never transmitted. File paths are hashed rather than stored by default, and AI prompts and responses are never recorded.
  • Model Context Protocol support, shipped disabled. Every server must be enabled individually and carries a plain-English disclosure of what it can see; secrets are held in the existing DPAPI-backed store rather than written into configuration.
  • Close the open threat model (Ctrl+W), with an unsaved-changes guard and a full reset of document state. Previously a model could only be replaced, never closed.
  • Microsoft Threat Modeling Tool stencil artwork in the diagram view, extracted at run time from the user's own MTMT installation. The artwork is Microsoft's and is deliberately never redistributed with this app.
  • File attachments in the Edit with Copilot panel, so an architecture diagram or document can be handed over directly instead of described in prose. Vision-only content is gated on the selected model actually supporting vision.

Changed

  • GitHub Copilot SDK 1.0.2 → 1.0.11, which moves the bundled Copilot runtime to CLI 1.0.79. Verified with a live probe, not just a clean compile. Note that the available model list is served by the GitHub API and is not gated by the SDK version — both runtimes return the same models.
  • Fluent 2 design foundation, with the whole app re-skinned onto shared design tokens.
  • Test host updated to Microsoft.NET.Test.Sdk 18.9.0 and coverlet.collector 10.0.1.

Fixed

  • A shipping WCAG contrast failure. The score and band chips used colours that failed AA against their own background (2.78:1 and 4.29:1). All three states now pass (5.64:1, 4.55:1, 6.40:1).
  • An unreadable model dropdown, which rendered the raw record text (AiModel { Id = …, SupportsVision = True }) inside a 190px control.
  • A gap in the archive guard. A crafted Office file whose central directory under-reported an entry's size passed inspection and then silently truncated content. Such a mismatch is now detected and rejected.
  • Ingestion of shared file extensions. .md is also a diagram extension, because markdown can embed a Mermaid block, so plain markdown was being rejected as "not a diagram". Shared extensions now fall back to document extraction.
  • A load-sensitive test that waited a fixed interval for an asynchronous progress callback and failed on a busy machine.
  • Documentation corrected on the relationship between the score, the verdict and the CI band: the FAIL band and the NOT READY verdict are the same outcome, not two independent ones.

2.0.3 — 2026-08-09

Changed

  • Product copy now matches the shipped feature set. The header subtitle, About dialog, package description and docs previously said the app also creates threat models, but model creation is in beta and hidden in the current build. Everywhere now reads "review, fix & analyze", and the Create capability (guided wizard + Copilot DFD extraction from a description, image or OpenAPI spec) is clearly labelled beta / coming soon. No functional change — the Create and Assistant tabs were already hidden. The create and openapi commands remain available in the CLI.

Added

  • Enterprise-grade documentation set, for security review and managed rollout:
    • Data handling & privacy — every network destination and on-disk path, the secret redaction applied before any AI prompt, and confirmation that no telemetry or analytics are collected.
    • Enterprise deployment — silent-install switches, MSI UpgradeCode / Inno AppId for detection rules, Intune / Configuration Manager / Group Policy guidance, disabling update checks fleet-wide, air-gapped operation, VDI notes, and CI/CD gating with the CLI.
    • Third-party notices — full component inventory with licenses.
    • Support policy — severity definitions and response targets.
    • Code of conduct, CODEOWNERS and Dependabot configuration.
  • Security policy expanded with vulnerability-response targets, a supported-versions table, and the controls protecting the tool itself (untrusted-file parsing, prompt-injection detection, DPAPI credential storage, export formula-injection neutralization, supply chain).

Notes

  • The verdict and 0–100 review score remain 100% deterministic; Copilot stays advisory.

2.0.2 — 2026-08-09

Changed

  • Canonical project home is now ArasaniRohithReddy. Following the repository transfer, every link and identifier the app carries now points to the new owner: the in-app update check, the About dialog and Help menu links (releases, install & user guide, FAQ, issues, security, license), the SARIF report's informationUri, and the installer/package publisher, URLs, and code-signing identity (CN=ArasaniRohithReddy). The old Rohithreddy7123 URLs still resolve via GitHub's automatic redirect, but the app no longer relies on it — existing installs are offered this update through that redirect and are canonical afterwards.

Notes

  • No change to behavior, the verdict, or the 0–100 review score — this is an identity/branding release. The score and verdict remain 100% deterministic; Copilot stays advisory only.
  • The MSIX package identity changed with the publisher, so an existing MSIX install updates side-by-side; MSI, Setup.exe, and portable users update normally (in-app from v1.0.4+).

2.0.1 — 2026-07-27

Changed

  • Diagram edits no longer freeze the UI on large models. Adding, renaming, deleting, or connecting elements — and the Save changes / Reset diagram commands — now run the re-parse and re-review on a background thread, so the app stays responsive on big threat models.

Fixed

  • CLI: a dangling or unknown option (e.g. a trailing --model with no value) now reports a clear error and exits with code 1 instead of being mistaken for the input file path; an invalid --issues-format is rejected with the list of valid choices.

Security

  • The in-app device-flow GitHub token is now passed directly to the Copilot SDK instead of being set as a process-wide environment variable, so it can no longer be inherited by other processes the app launches (browser, cmd, the Threat Modeling Tool).

2.0.0 — 2026-07-26

The 2.0 line opens with a correctness release: models you fix in the app now reliably reopen in the Microsoft Threat Modeling Tool, Copilot's advisory text renders properly, and a whole-app audit (run with Claude Opus 4.8 + Opus 5) hardened every write path.

Fixed

  • App-fixed .tm7 files now open in the Microsoft Threat Modeling Tool. Two defects made TMT reject a saved model as "could not be deserialized / may be corrupted": the threat State was written as "Needs Investigation" (TMT's ThreatState enum only accepts NeedsInvestigation), and whole-model threats wrote empty Guid fields. Both are fixed and verified against TMT's own serializer.
  • Fixed a TMT dashboard crash ("an item with the same key has already been added"). TMT identifies a threat by TypeId + Source + Flow + Target; several distinct threats added to one element/category (e.g. OWASP-LLM risks) now get distinct TypeIds so they never collide.
  • The --baseline Create path no longer produces corrupt files (an XML declaration/encoding mismatch); carried KnowledgeBase and multi-line names are preserved byte-for-byte.
  • Copilot output now renders as formatted text — the critique, per-finding guidance, and mitigation plan show real bold, italic, code, and bullet lists instead of literal Markdown symbols.

Changed

  • Whole-app correctness audit. Hardened AI-response handling (malformed/partial JSON no longer crashes; AI failures never abort the deterministic report or verdict), fixed a triage-state parser that could mark open threats as mitigated, made model parsing/diff/critique robust to duplicate or blank element ids, stopped a portable-update helper from hanging invisibly, neutralized CSV formula-injection in exports, and ensured the bundled Copilot runtime is never orphaned on exit.
  • Newly added diagram elements now default in scope (a cloned template could previously make them out-of-scope and change the deterministic result).

Notes

  • Verdict and 0–100 review score remain 100% deterministic. Copilot is advisory only.
  • Known follow-ups: diagram-edit responsiveness on very large models, and published update-asset checksums, are planned for a later 2.x release.

1.0.11 — 2026-07-03

Added

  • "Deep analysis for all" button on the Findings tab, beside "Explain all with Copilot". It runs the full deep analysis (DREAD, mitigation plan, attack tree, and verification tests) for every finding at once, stored per-finding and reusable in exports. Because each finding is several premium requests, it asks for confirmation (showing the estimated cost) first. Advisory only — the verdict stays deterministic.

Changed

  • Consistent button styling & sizing across the app. Buttons now use one of three deliberate tiers (default / compact / inline) instead of ad-hoc per-button sizes: the coverage-panel buttons match the standard text size; the Diagram, Create, and chat action buttons share one compact size; and the AI-provider and review-options dialogs now use the app's shared button styles (rounded chrome, hover/focus states) rather than raw system buttons.

1.0.10 — 2026-07-03

Fixed

  • Literal \u2026 / \u2014 shown in the UI. A few labels/tooltips had C#-style Unicode escapes embedded in XAML (where they aren't interpreted), so an ellipsis appeared as the raw text \u2026 (e.g. on the Analyze gaps with Copilot and Prioritize with Copilot buttons) and an em-dash as \u2014 (a couple of tooltips and the diagram-assistant title). All are now rendered as proper and .

1.0.9 — 2026-07-03

Fixed

  • "Check for updates" could wrongly say "You're on the latest version" when it actually failed. GitHub's unauthenticated API has a 60-requests/hour limit; when it was hit (HTTP 403), the check treated the failure as "up to date." Now:
    • it falls back to the releases.atom feed (served from github.com, not subject to that API rate limit) so the check keeps working — reconstructing the download links from the release tag; and
    • if it genuinely can't reach GitHub, it says so ("Couldn't reach GitHub… try again later") instead of claiming you're up to date.

1.0.8 — 2026-07-03

Added

  • Sign in to GitHub Copilot from inside the app — no external CLI required. If you're not already signed in, the Sign in to Copilot button now opens an in-app dialog that runs GitHub's OAuth device flow (the same flow and client the GitHub Copilot CLI uses): it shows a one-time code, you approve it in your browser, and the app connects and lists your models. The token is stored DPAPI-encrypted per-user.

Changed

  • Copilot authentication is now layered (best UX first): the app uses your existing GitHub Copilot CLI / gh sign-in automatically when present, and only offers the in-app device-flow sign-in if you're not already signed in. Either way, the deterministic review needs no sign-in.

1.0.7 — 2026-07-03

Added

  • In-app "Sign in to GitHub Copilot". When the AI features aren't available because you're not signed in, the header now says so clearly and shows a Sign in to Copilot button that runs the bundled GitHub Copilot CLI's sign-in (browser / device-code) — then reconnects and lists your models automatically. No token to paste.

Changed

  • Clearer prerequisites everywhere: the AI features need an active GitHub Copilot subscription and being signed in (via the in-app button, gh auth login, or a COPILOT_GITHUB_TOKEN / GH_TOKEN / GITHUB_TOKEN fine-grained PAT with the "Copilot Requests" permission). Documented in the README, install guide, user guide, and FAQ. The deterministic review still needs none of this.

1.0.6 — 2026-07-03

Added

  • Choose the fix source for all fixes at once. The Fix tab now has a "Use for all: Built-in / Copilot" control that switches every fix to the deterministic built-in content or to the Copilot draft in one click — alongside the existing "Draft with Copilot" button (generates the drafts) and the per-row Built-in / Copilot radios (individual override). So you can pick the source globally or per fix.

1.0.5 — 2026-07-03

Fixed

  • "Analyze gaps with Copilot" and "Prioritize with Copilot" buttons stayed greyed out on the Overview tab even after a model was loaded. Their enable-state wasn't being re-evaluated when the review completed (a missing change-notification), so they were stuck disabled. Both now enable as soon as a .tm7 is reviewed, exactly like the other Copilot buttons. (These are independent, advisory actions — using "Draft with Copilot" in the Fix tab never disabled them.)

1.0.4 — 2026-06-28

Changed

  • In-app updates — clicking Download on the update banner now downloads the new build inside the app, with a progress bar, instead of opening a browser. It automatically picks the installer that matches how you installed (MSI, Inno -setup.exe, portable .zip, or MSIX), then offers Install & restart: the app closes, updates in place, and reopens on the new version. A What's new link still opens the full release notes in the browser, and the browser download remains as a fallback when no matching installer is found.

1.0.3 — 2026-06-28

Added

  • About dialog — a proper About page (header Help ▾ → About) showing the app version, publisher, what the app does, the deterministic-verdict promise (the verdict and 0–100 score come from the rubric engine, never AI; Copilot is advisory; models are reviewed locally), the MIT license, and direct links to the repo, issues, and releases.
  • Help menu in the header with direct links — User guide, Installation guide, FAQ, Report an issue, View all releases, View on GitHub, and Check for updates — so help and the issue tracker are one click away.

Changed

  • Header subtitle now reads "Review, fix, analyze & create Microsoft Threat Modeling Tool (.tm7) threat models" — it previously omitted analyze — and wraps cleanly on narrow windows.

1.0.2 — 2026-06-28

Added

  • In-app update check — on startup (and via a "Check for updates" link in the status bar) the app checks the release hub for a newer build and shows a dismissible banner with Download / Skip this version / Later. It's notify-only (never auto-applies), works for every install format, fails soft when offline, and can be disabled in %APPDATA%\ThreatModelReviewer\update.json.

1.0.1 — 2026-06-28

Added

  • MSI installer (…-x64.msi) built with WiX — a single, dual-scope installer that lets the user choose per-machine (all users / Program Files) or per-user (no admin) at install time, with a Start-Menu shortcut and Apps & features entry.
  • Authenticode signing of every artifact (portable .exe, MSI, installer .exe, MSIX). The build pipeline signs with your CA/EV certificate via -CertPfx / -CertThumbprint; otherwise a self-signed certificate is used.

Notes

  • Artifacts are currently self-signed, so SmartScreen still warns on first run until a CA-issued (ideally EV) certificate or Azure Trusted Signing is used. See docs/INSTALL.md.

1.0.0 — 2026-06-27

First public release.

Added

  • Deterministic review of Microsoft Threat Modeling Tool .tm7 files (and OWASP Threat Dragon .json): a stamped NOT READY / READY-WITH-NOTES verdict plus a 0–100 review score with a letter grade across the Four-Question dimensions. The verdict is never produced by AI.
  • ~70 rubric checks spanning structural completeness, STRIDE-per-element coverage, triage & mitigation quality, trust-boundary/identity, data protection, network, logging/detection, deprecated cryptography, software supply chain, mismodeled stencils, and a deep AI/agentic surface (OWASP LLM Top 10 2025, OWASP Agentic, MITRE ATLAS). Each finding cites authoritative references (OWASP, MITRE, CWE, Microsoft Learn) and ships built-in "what it means / how to fix" guidance.
  • STRIDE-per-element coverage matrix, Threats-by-interaction breakdown (worst-gap-first), and a deterministic Framework coverage scorecard (OWASP Top 10 2021 + STRIDE).
  • Fix / remediation with round-trip write-back to a valid .tm7 (add missing threats, triage Not-Started, draft justifications, fill out-of-scope reasons).
  • Create a new .tm7 from a guided wizard or from Copilot DFD extraction.
  • Copilot enrichment (optional, advisory): explain findings, deep analysis (DREAD / attack tree / Gherkin), draft fixes, whole-model critique, framework-gap analysis, and interaction-triage planning — each independent and powered by your GitHub Copilot seat.
  • Exports: HTML, PDF, Markdown, CSV, JSON, SARIF reports + issue-tracker work items (GitHub / Azure DevOps / Jira / JSON), with an optional pre-export "include Copilot guidance / deep analysis" step.
  • Packaging: portable self-contained .exe (zip), Inno Setup installer, and a signed MSIX package.