ReARM 26.08.95: Teams as a First-Class Entity, KEV Tracking, and Notification Routing
We're announcing a major release of ReARM v26.08.95. Detailed information is available on its release view on the ReARM Demo instance. ReARM Pro installations either have already been upgraded or will be upgraded according to upgrade policies; ReARM CE users are encouraged to upgrade to benefit from the changes described below and improved security posture.
Teams
The headline of this release is Team as a first-class entity — the organization's addressable unit for ownership, notification routing, and assignment. A new Teams tab lets you create and edit teams with per-member roles, and teams can own components: org-wide regex assignment rules map components to owning teams automatically, with a clear-owner action for exceptions, and owner assignment now joins the staged component-settings save flow. Team notification channels are usable as a route target, and a team can turn on notifications for the components it owns.
Notifications
Notification subscriptions have been consolidated: one route per subscription, with every filter gathered in one place, plus an owner-routing target so findings can be delivered to whoever owns the affected component. The subscription editor is tidier, and ReARM CE now exposes the notification surface the CE backend already supported. ReARM Pro additionally gains instance-event deployment notifications — with the subscription UI to drive them — along with CEL filter validation at save time and an option to notify component owner.
KEV Tracking
Known Exploited Vulnerabilities are now a first-class series on the findings-over-time charts, with a series filter to isolate them, and a matching KEV-only filter in the findings modal that arrives pre-enabled when you open it from the KEV chart series — so going from "we have KEV exposure" to the exact list of affected findings is a single click.
Findings, Changelog, and VEX
Release-level findings recompute is available on demand, and the findings chart gains filter with select/deselect-all. The changelog surfaces re-scan visibility, showing over-time changes with arrival-dated attribution. On the VEX side, component, branch, and release are now linkified on VEX proposals, and VEX statement proposals resolve a human-readable scope.
Reliability
This release includes number of reliability improvements across the platform, mainly around OCI registry operations and handling of historical finding events.
Dependency Updates
This release contains a number of dependency updates, including those fixing underlying CVEs in dependencies — container CVEs are back to zero, and the OCI Artifact Service moves to Go 1.26.6 on a scratch release image.
Release Identification
We are continuing to publish TEIs for all ReARM releases. TEI for this release: urn:tei:purl:demo.rearmhq.com:pkg:github/relizaio/rearm@26.08.95.