Kulshan changelog.
A timeline of Kulshan releases. Newest first. See the upstream changelog for patch-level details.
0.4.2 · 2026-07-20
Policy correction and scanner integrity.
Three S3 entries in the published IAM policy used AWS API operation names instead of IAM action names. They granted nothing, but the scanner could treat a resulting authorization failure as a clean result. The IAM action names are now corrected, and the scanner reports "could not check" when a required evaluation fails rather than marking it clean. The composed policy hash has been updated.
0.4.1 · 2026-07-18
Safer, more reliable evidence collection.
Windows console output is UTF-8 safe, bounded AWS and local data calls cannot leave the MCP server hung, and domain failures are reported as errors rather than successful envelopes.
0.4.0 · 2026-07-17
Coverage becomes explicit.
Structured preflight and pack-readiness reporting make it clearer which evidence sources were available. Coverage disclosure now follows reports, SARIF output, and local history.
0.3.0 · 2026-07-15
AWS environments remain isolated and attributable.
Identity-based onboarding, payer binding, federated local history, and consolidated reports support complex AWS environments while preserving source and connection metadata.
0.2.0 · 2026-07-07
Investigation briefs become structured.
Local history, workspaces, evidence exports, configuration, and human-review fields made investigations repeatable without turning findings into automated decisions.
0.1.0 · 2026-04-21
The read-only foundation.
The first release established local AWS evidence collection, multiple output formats, diagnostic packs, and a published read-only IAM boundary.