1.5.47
Released 25 Aug 2026
Improved
-
Revocation monitoring now also covers retained previous certificate versions. The periodic CA revocation check no longer looks only at the current certificate: previous versions kept in history are checked too, and a version revoked at the CA (for example after reporting a key compromise directly to the CA) is automatically excluded from rollback candidates and raises a warning notification. The live certificate is unaffected.
-
The certificate Discovery tab groups endpoints by IP address. An address that serves the certificate under many names (a wildcard, an ingress) now collapses to a single row you click to expand and see each name — instead of one long flat list. Each row also shows how discovery found it (SAN crawl, cloud DNS, reverse DNS, and so on).
-
The Discovery Inventory endpoint list groups by IP address too. The same collapse-and-expand treatment now applies on the inventory page: one row per address, click (or press Enter) to unfold its names. Group rows can be expanded with the keyboard on every view.
-
Large discovery sources: the Certificates tab now loads page by page. A source that discovered tens of thousands of certificates (a CT log, a wide network range) previously tried to load them all at once and could stall; the tab now fetches one page at a time and the tab header shows the true total.
-
The source form's target estimate moved under Max Targets — and warns when it exceeds it. While defining a CIDR or hostname source, the "≈ N base targets" hint now shows directly under the Max Targets field and turns into a warning when the estimate is larger than the configured cap, since the scan would stop at the cap.
-
Cloud DNS discovery scans now explain zone failures. When a provider zone cannot be listed — missing permission, provider rate limit, a network error — the scan's job log names each failed zone and the reason, instead of silently scanning less than you asked for.
Changed behaviour
- Discovery size estimates are rate-limited. The "estimate" probe used when defining a discovery source now allows 30 requests per minute per project; beyond that it briefly answers with HTTP 429. The source forms are unaffected in normal use — this only guards against scripted hammering.
Fixed
-
The Discovery tab no longer labels endpoints "unmanaged". Every endpoint on that tab is, by definition, serving the certificate you're viewing, so the status column always read a confusing unmanaged; it has been replaced with the discovery method that found each endpoint.
-
A discovery scan can no longer wrongly report endpoints as disappeared. If part of a scan's coverage could not be verified (an internal check failed mid-scan), endpoints are now kept instead of being expired. A scan taken over after a stalled worker also stops writing immediately, so it cannot race the replacement scan's results.