New Platform Features
- Embedded Draw.io diagramming and import/export in Draw.io's own format as well as external formats. More details can be found here. Note: The diagram is completely embedded and no data is transmitted outside of the IriusRisk instance.
- Clone product. More details here.
- New settings option to remove or keep threats that are no longer applicable based on the rules. See documentation here.
- New SAML configuration option to set the entityId parameter. This allows integrating multiple IriusRisk instances with the same Identity Provider. See documentation here.
Upgrading from 2.x to 3
Threat models in IriusRisk will automatically be migrated to the new version and the diagram automatically converted into draw.io format. Note that the XML import of v2.x models is not supported in version 3.x. Make sure all the models that need to be upgraded are loaded into the IriusRisk instance before upgrading.
XML Compatibility for Products and Libraries
Although the XML for Product is not compatible on version 3 with previous versions. The XML for libraries is fully compatible between versions 2 and 3.
To deploy or upgrade to version 3 edit the docker-compose.yml file and change the image name to: continuumsecurity/iriusrisk-prod:tomcat8-3
For the .war file installation the name of the war file is: iriusrisk-3.war
Full upgrade instructions can be found here.
This release also delivers multiple bug fixes including: