Highlights
ποΈ Infrastructure & Performance
- build(deps): bump github/codeql-action from 4.35.4 to 4.35.5 @dependabot[bot] (#8623)
- build(deps): bump step-security/harden-runner from 2.19.2 to 2.19.3 @dependabot[bot] (#8622)
π¦ Dependencies
- build(deps): bump github/codeql-action from 4.35.4 to 4.35.5 @dependabot[bot] (#8623)
- build(deps): bump step-security/harden-runner from 2.19.2 to 2.19.3 @dependabot[bot] (#8622)
- build(deps): bump cia.project.versions.asm from 9.9.1 to 9.10 @dependabot[bot] (#8621)
Political Analysis Enhancements
Changes in this release continue to enhance the Citizen Intelligence Agency (OSINT) platform's capabilities for monitoring political figures and institutions, providing improved insights into:
- Political performance metrics
- Institutional transparency
- Decision-making analysis
- Risk assessment
π Hack23 ISMS Policies & Governance
Hack23 is committed to transparency and evidence-based security. Our complete Information Security Management System (ISMS) is publicly available:
Coverage: 32 ISMS policies β’ 100+ security controls β’ ISO 27001:2022 β’ NIST CSF 2.0 β’ CIS Controls v8.1
π‘οΈ Security & Compliance
SLSA Build Attestations
Artifact Attestations Available:
- DEB Package Build Provenance - SLSA Level 3 provenance for cia-dist-deb-2026.5.15.all.deb
- WAR Build Provenance - SLSA Level 3 provenance for citizen-intelligence-agency-2026.5.15.war
- DEB SBOM Attestation - Software Bill of Materials in SPDX format
- WAR SBOM Attestation - Software Bill of Materials in SPDX format
Security Posture
Security Scanning Results
π Quality & Testing
Code Quality Reports
Detailed Reports Available:
- Maven Site Documentation - Complete project documentation
- JaCoCo Test Coverage - Unit test coverage reports (80%+ line, 70%+ branch)
- JavaDoc API Documentation - Complete API reference
- SonarCloud Dashboard - Code quality metrics
Testing Standards
Per Secure Development Policy:
- β Minimum 80% line coverage
- β Minimum 70% branch coverage
- β Automated security scanning (SAST/DAST)
- β Dependency vulnerability checks
π» Technology Stack
Runtime: Java 26 (Feature Release) β’ Source: Java 21 (LTS) β’ Build: Maven 3.9.15 β’ Database: PostgreSQL 18
π Contributors
Thanks to @dependabot[bot] and dependabot[bot] for their contributions to this release!
Full Changelog: 2026.5.14...2026.5.15