← Back to all sparks
O

OpenCTI

ANALYTICS
Velocity5.0

Open cyber threat intelligence platform

OpenCTI ships weekly and is rebuilding its connector catalog into a marketplace.

threat-intelligenceconnector-marketplaceworkflow-approvalsbomenterprise-editionweekly-releases
Current state
OpenCTI runs a weekly CalVer release train on the current line plus a separate LTS branch that takes backported security work. The recurring theme across recent releases is the integrations surface: the connector catalog was redesigned into a faceted marketplace, connector status labels were renamed to Supported by Filigran and Supported by Community, and the new integrations experience closed its functional gaps around config import, works, sorting and next-run visibility. Workflow gained draft approval, full reset and protection against publishing a workflow that deletes an in-use status, and the legacy HTML editor was removed outright.
Where it's heading
Two directions are visible. One is commercial packaging — XTM Hub connection points, hero-style Enterprise Edition cards in settings, and the supported-by labelling all draw a line between vendor-backed and community connectors inside the product. The other is supply-chain and governance hygiene: SBOM generation with syft, documented SBOM format, admin-forced password changes, session IDs recorded in audit logs, and a configurable webhook deny list. The LTS branch confirms the split audience — enterprises on a slow line getting CVE backports while the weekly line moves.
Prediction
Expect the marketplace framing to keep hardening the commercial boundary — paid or vendor-supported connectors surfaced distinctly from community ones — and workflow approval to extend from drafts into other publishing paths.

Recent moves

  1. 20h ago

    Weekly release: data sanity stop, SBOM docs, merge performance

    A mostly corrective weekly release: data sanity operations can now be stopped, SBOM format is documented, and a merge that hung on entities with large relationship counts because of an O(n×m) scan was fixed. Incremental upkeep on the current line rather than new surface.

    View source ↗
  2. 5d ago

    Weekly release: integrations experience and draft approval workflow

    Closes the functional gaps in the new integrations experience — config import, works, facets, sorting, next run — and adds a draft approval workflow plus TAXII client errors surfaced in the UI. The XTM Hub connection points and reworked Filigran experience settings in the same release show the commercial layer being wired into the same screens.

    View source ↗
  3. 12d ago

    Weekly release: connector catalog becomes a faceted marketplace

    The release that reframes the connector catalog as a faceted marketplace, retires the legacy HTML editor and its feature flags, and hardens workflows with full reset and a guard against publishing one that deletes an in-use status. Also adds a configurable webhook URI deny list and admin-forced password changes.

    View source ↗
  4. 18d ago

    Weekly release: live stream, groups and widget fixes

    A fix-only weekly release covering live streams with advanced-option filters, group detail pages, workbench type selection and dashboard widget periods. No new capability.

    View source ↗
  5. 19d ago

    Weekly release: SBOM generation, custom views, ESM frontend

    Adds syft-based SBOM configuration, extends custom views with date ranges and attribute widgets, relabels connector support tiers to Supported by Filigran and Supported by Community, and migrates the frontend to ESM. The support-tier rename is small in code and large in positioning.

    View source ↗
  6. 25d ago

    LTS 6: security backports and dependency updates

    A long-term-support release carrying critical and security fixes — a starlette upgrade for CVE-2026-54282, direct axios, dompurify and graphiql updates, plus playbook enrichment fixes. Confirms the two-track model: enterprises on LTS get security work while the weekly line carries features.

    View source ↗