ReARM 26.10.52: Agent Task Boards, CLI Browser Login, and Richer Vulnerability Findings
We're announcing a major release of ReARM v26.10.52. Detailed information is available on its release view on the ReARM Demo instance. ReARM Pro installations either have already been upgraded or will be upgraded according to upgrade policies; ReARM CE users are encouraged to upgrade to benefit from the changes described below and improved security posture.
Agent Task Boards (Preview)
The headline of this release is a preview of agent task boards: a way to coordinate teams of AI coding agents through configurable role-based pipelines, i.e. architect → coder → tester, with a coordinator seat that registers, orders, splits and merges work while people stay in control. A task is only complete once its pull requests have merged. Every hop publishes versioned documents (designs, implementation notes, test reports, questions) to a git repository, and review items route work back to whoever has to fix it.
People can approve, approve with corrections, decide review items, place holds, reopen tasks and set budgets, and board events that need a person arrive as notifications. Usage is attributed per task and per hop, with hop allowances, task budgets and a spend breakdown that adds up to the total. Boards can be applied and exported as declarative files, and dedicated board, task, documents and Agents views show who is working on what. Agent task boards are available on both editions; ReARM Pro additionally scopes boards to perspectives and adds CEL coverage gates on documents.
AI Agent Sessions
Agent sessions now report token usage and cost from Claude Code transcripts, priced against an organization model catalogue that can be edited and merged. Each session records how it was opened, the agent tool's own session id, and the tasks and boards it worked on; board work counts as session activity, and an idle session is warned before it is closed. ReARM Pro adds agent session policies.
CLI Browser Login and API Keys
rearm login now signs the CLI in from the browser using device authorization. The approver grants permissions bounded by their own, CLI sessions rotate their refresh tokens, and a key can set a hard end for device-login sessions. On the API key side, users can create personal API keys capped by their own permissions and request keys from administrators. Secrets can carry an expiry, and two-secret rotation allows zero-downtime key changes, with a status kill switch for emergencies.
Federated identity trust rules let GitHub Actions identity tokens authenticate without a stored secret, and programmatic clients get a dedicated GraphQL endpoint (/api/programmatic/graphql) with token exchange.
Richer Vulnerability Findings
Any finding id now opens an in-app vulnerability details panel that shows when each source last changed and can refresh from Dependency-Track. ReARM now shows CVSS and EPSS scores for findings and aggregates them per release, where they are clearly visible on the release view. Each finding shows fixed-in versions taken from the advisory's affected ranges, along with the latest version of the affected component, so it is easier to see what an upgrade would actually fix. Findings are matched to their release SBOM component on the server and grouped by component in the findings view.
Dependency-Track 5 is now the recommended version, with Dependency-Track 4 still supported. Several accuracy fixes ensure one record per vulnerability even when its CVE arrives late, and stop advisories from one source replacing each other.
Build Integrity
Components can now be locked, and commits can be claimed (attested or disowned), with agent-authored commits recognized. ReARM Pro adds policy-raised locks that release once claimed, a Build Integrity inbox, and named action guards written in CEL, editable from component and organization settings.
SBOMs, Exports and FDA Readiness
Merged SBOMs now keep the tools that produced their inputs, and every export names the ReARM version in its tool entry. Exports gain per-export options for support and internal metadata. Processed BOMs carry their own serial number, processed artifacts are immutable, and a raw download returns exactly the uploaded bytes. VDR references and CLE events are schema-valid, with advisory ranges emitted as vers ranges.
For FDA readiness, components get per-component support attestation, support-date suggestions where no attestation exists, and organization-level FDA statements. ReARM Pro adds a device support window, fleet risk and per-release FDA assessment narratives.
Security and Reliability
This release hardens every write path: each upsert, programmatic upload, VCS link, source code entry and release reference now checks that the caller owns the record and everything it points to. Stored user-supplied regular expressions are bounded, access-controlled downloads are not cached, and a refused call rolls back everything it wrote. Version assignment is serialized per component and never issues a lower version, and approval requirements count distinct voters. Further fixes protect stored artifacts and configuration from accidental wipes, and keep the platform steady when rebom or Dependency-Track is unreachable.
Dependency Updates
This release contains a number of dependency updates, including CVE sweeps across the backend, UI and rebom images and a Keycloak update to 26.8.0. ReARM users are encouraged to upgrade to this release to benefit from these fixes.