<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://docs.bugcrowd.com/changelog.xml" rel="self" type="application/atom+xml" /><link href="https://docs.bugcrowd.com/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-09-16T05:46:36+00:00</updated><id>https://docs.bugcrowd.com/changelog.xml</id><title type="html">Bugcrowd Docs | Changelogs</title><subtitle>Bugcrowd user documentation</subtitle><entry><title type="html">Linking Vulnerability Detections to Jira</title><link href="https://docs.bugcrowd.com/changelog/customers/linking-vulnerability-detections-to-jira/" rel="alternate" type="text/html" title="Linking Vulnerability Detections to Jira" /><published>2026-09-06T00:00:00+00:00</published><updated>2026-09-06T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/linking-vulnerability-detections-to-jira</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/linking-vulnerability-detections-to-jira/">&lt;p&gt;Customers with the Jira integration enabled can now link and push &lt;strong&gt;Vulnerability Detections&lt;/strong&gt; (surfaced in the Security Inbox from continuous scanning) to Jira issues, in addition to submissions. This keeps remediation work tracked in Jira in sync with the risk data in Crowdcontrol.&lt;/p&gt;

&lt;p&gt;From a Vulnerability Detection’s &lt;strong&gt;Integrations&lt;/strong&gt; panel, use &lt;strong&gt;Push&lt;/strong&gt; to create a new Jira issue populated with the detection’s details, or &lt;strong&gt;Link&lt;/strong&gt; to connect it to an existing Jira issue. Once linked, updates can be pushed to Jira, comments stay in sync, and the link can be edited or removed at any time.&lt;/p&gt;

&lt;div class=&quot;uk-alert-primary&quot; data-uk-alert=&quot;&quot;&gt;&lt;p&gt;Jira integration must already be configured for your organization before you can link a Vulnerability Detection to Jira. Automated creation rules and attachment syncing currently apply to submissions only.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;For full details, see &lt;a href=&quot;/customers/integration-management/jira/linking-vulnerability-detections-to-jira/&quot;&gt;Linking a Vulnerability Detection to Jira&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="integration-management" /><summary type="html">Customers with the Jira integration enabled can now link and push Vulnerability Detections (surfaced in the Security Inbox from continuous scanning) to Jira issues, in addition to submissions. This keeps remediation work tracked in Jira in sync with the risk data in Crowdcontrol.</summary></entry><entry><title type="html">Request a Response Expiration Removal</title><link href="https://docs.bugcrowd.com/changelog/researchers/rar-expiration-removal/" rel="alternate" type="text/html" title="Request a Response Expiration Removal" /><published>2026-08-25T00:00:00+00:00</published><updated>2026-08-25T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/researchers/rar-expiration-removal</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/researchers/rar-expiration-removal/">&lt;h2 id=&quot;request-a-response-rar-your-requests-no-longer-expire&quot;&gt;Request a Response (RaR): Your requests no longer expire&lt;/h2&gt;

&lt;p&gt;We’ve updated how Request a Response (RaR) works. Open RaRs no longer expire after a fixed period. Your request now stays open until it is resolved, so it will no longer be closed automatically before you receive an answer.&lt;/p&gt;

&lt;p&gt;What this means for you:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;There is no longer a countdown or expiry timer on your RaRs.&lt;/li&gt;
  &lt;li&gt;Each RaR shows the date it was created, so you can track how long it has been open.&lt;/li&gt;
  &lt;li&gt;As before, when one of your open RaRs is resolved, it frees up 1 active account slot allowing you to open a new RaR, but permanently counts as 1 of your 2 allowed requests for the specific submission.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All RaR activity continues to be recorded in the submission’s Activity.&lt;/p&gt;</content><author><name></name></author><category term="researcher" /><summary type="html">Request a Response (RaR): Your requests no longer expire</summary></entry><entry><title type="html">Request a Response Expiration Removal</title><link href="https://docs.bugcrowd.com/changelog/customers/rar-expiration-removal/" rel="alternate" type="text/html" title="Request a Response Expiration Removal" /><published>2026-08-25T00:00:00+00:00</published><updated>2026-08-25T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/rar-expiration-removal</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/rar-expiration-removal/">&lt;h2 id=&quot;request-a-response-rar-requests-no-longer-expire-plus-new-inbox-filters&quot;&gt;Request a Response (RaR): Requests no longer expire, plus new inbox filters&lt;/h2&gt;

&lt;p&gt;We’ve updated how Request a Response (RaR) works. Open RaRs no longer expire automatically after a fixed period. Each RaR now stays open until your team responds or resolves it, so a researcher’s request will not close on its own before it is answered.&lt;/p&gt;

&lt;p&gt;What this means for you:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;There is no longer a countdown or expiry timer on an RaR.&lt;/li&gt;
  &lt;li&gt;Each RaR shows the date it was raised, so you can see how long it has been open.&lt;/li&gt;
  &lt;li&gt;New inbox filters let you view requests by status: select “Active requests to Customers” to quickly find what needs your attention or “Resolved requests to Customers” to see those already handled.&lt;/li&gt;
  &lt;li&gt;We encourage responding to open RaRs promptly to keep submissions moving and maintain positive researcher engagement.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No action is required. All RaR activity continues to be recorded in the submission’s Activity for transparency.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Request a Response (RaR): Requests no longer expire, plus new inbox filters</summary></entry><entry><title type="html">Generating Vulnerability Detection Report</title><link href="https://docs.bugcrowd.com/changelog/customers/generating-vulnerability-detection-report/" rel="alternate" type="text/html" title="Generating Vulnerability Detection Report" /><published>2026-08-25T00:00:00+00:00</published><updated>2026-08-25T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/generating-vulnerability-detection-report</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/generating-vulnerability-detection-report/">&lt;p&gt;Bugcrowd customers can now generate a Vulnerability Detection Report at the organization level. The report is delivered as a PDF summarizing vulnerability detections found across your organization’s assets, scoped by date range, CVSS severity, and asset filters, and grouped either by asset or by vulnerability.&lt;/p&gt;

&lt;div class=&quot;uk-alert-primary&quot; data-uk-alert=&quot;&quot;&gt;&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: The Vulnerability Detection Report is only available when Asset Inventory is enabled for your organization and your organization has an active vulnerability scan configured.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/customer/vulnerability-detection-report/configure-report.png&quot; alt=&quot;create vulnerability detection report&quot; /&gt;&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="reporting-organization" /><summary type="html">Bugcrowd customers can now generate a Vulnerability Detection Report at the organization level. The report is delivered as a PDF summarizing vulnerability detections found across your organization’s assets, scoped by date range, CVSS severity, and asset filters, and grouped either by asset or by vulnerability.</summary></entry><entry><title type="html">Savant Pathseeker Early Access (1.0)</title><link href="https://docs.bugcrowd.com/changelog/customers/pathseeker-early-access/" rel="alternate" type="text/html" title="Savant Pathseeker Early Access (1.0)" /><published>2026-08-17T00:00:00+00:00</published><updated>2026-08-17T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/pathseeker-early-access</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/pathseeker-early-access/">&lt;p&gt;Savant Pathseeker is now available in Early Access for autonomous penetration testing. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core capabilities and product scope, step-by-step guidance for launching an autonomous test, adding assets mid-setup, running authenticated tests behind login (including external identity providers), and pushing validated findings to the Security Inbox.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="autonomous-pentest" /><summary type="html">Savant Pathseeker is now available in Early Access for autonomous penetration testing. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core capabilities and product scope, step-by-step guidance for launching an autonomous test, adding assets mid-setup, running authenticated tests behind login (including external identity providers), and pushing validated findings to the Security Inbox.</summary></entry><entry><title type="html">Savant Vista Public Beta (1.0)</title><link href="https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta/" rel="alternate" type="text/html" title="Savant Vista Public Beta (1.0)" /><published>2026-07-14T00:00:00+00:00</published><updated>2026-07-14T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/savant-vista-public-beta/">&lt;p&gt;Savant Vista is now available in Public Beta for asset discovery and vulnerability scanning. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core concepts and product scope, step-by-step how-to guides for estate discovery, vulnerability baseline setup, and launching an autonomous test, and updated detailed reference articles reflecting the current platform UI, asset model, and scan behavior.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><category term="asset-management" /><summary type="html">Savant Vista is now available in Public Beta for asset discovery and vulnerability scanning. The documentation suite has been updated to support onboarding and day-to-day use, including a new overview article covering core concepts and product scope, step-by-step how-to guides for estate discovery, vulnerability baseline setup, and launching an autonomous test, and updated detailed reference articles reflecting the current platform UI, asset model, and scan behavior.</summary></entry><entry><title type="html">VRT Update (1.19.1)</title><link href="https://docs.bugcrowd.com/changelog/customers/vrt-update-119/" rel="alternate" type="text/html" title="VRT Update (1.19.1)" /><published>2026-07-08T00:00:00+00:00</published><updated>2026-07-08T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/vrt-update-119</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/vrt-update-119/">&lt;p&gt;Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been expanded to include Active Directory (AD) misconfigurations, Kerberos/SCCM abuse vectors, and server security misconfigurations (P1–P5). SSRF classifications have also been streamlined by replacing legacy categories with more granular SSRF metrics.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">Bugcrowd’s Vulnerability Rating Taxonomy (VRT) has been expanded to include Active Directory (AD) misconfigurations, Kerberos/SCCM abuse vectors, and server security misconfigurations (P1–P5). SSRF classifications have also been streamlined by replacing legacy categories with more granular SSRF metrics.</summary></entry><entry><title type="html">Verifying Your Identity</title><link href="https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity/" rel="alternate" type="text/html" title="Verifying Your Identity" /><published>2026-05-18T00:00:00+00:00</published><updated>2026-05-18T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/researchers/verifying-your-identity/">&lt;p&gt;Identity verification (IDV) is now required for all researchers prior to submitting reports to Managed Bug Bounty (MBB) programs — both public and private (excluding on-demand MBBs). This change strengthens platform integrity by reducing high volumes of low-quality submissions originating from newly created or rotating accounts. Verification requires researchers to complete a live selfie capture via webcam and upload a valid government-issued ID (passport, identity card, or driver’s license) through an embedded portal accessible directly from Account Settings under the Identity Verification tab. Researchers who have previously completed IDV — including those verified for payments or background checks — do not need to re-verify. The process supports multi-nationality verification and allows up to five attempts before a support ticket is required. For more information, visit &lt;a href=&quot;https://docs.bugcrowd.com/researchers/managing-account/account-settings/verifying-your-identity/&quot;&gt;Verifying Your Identity&lt;/a&gt;.&lt;/p&gt;</content><author><name></name></author><category term="researcher" /><summary type="html">Identity verification (IDV) is now required for all researchers prior to submitting reports to Managed Bug Bounty (MBB) programs — both public and private (excluding on-demand MBBs). This change strengthens platform integrity by reducing high volumes of low-quality submissions originating from newly created or rotating accounts. Verification requires researchers to complete a live selfie capture via webcam and upload a valid government-issued ID (passport, identity card, or driver’s license) through an embedded portal accessible directly from Account Settings under the Identity Verification tab. Researchers who have previously completed IDV — including those verified for payments or background checks — do not need to re-verify. The process supports multi-nationality verification and allows up to five attempts before a support ticket is required. For more information, visit Verifying Your Identity.</summary></entry><entry><title type="html">IP Restrictions</title><link href="https://docs.bugcrowd.com/changelog/customers/ip-restrictions/" rel="alternate" type="text/html" title="IP Restrictions" /><published>2026-05-14T00:00:00+00:00</published><updated>2026-05-14T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/customers/ip-restrictions</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/customers/ip-restrictions/">&lt;p&gt;The IP Restrictions feature allows organization admins to restrict access to their organization based on IP address. By configuring an allowlist, you can ensure that only users connecting from approved IP addresses or CIDR ranges are able to access data within the organization.&lt;/p&gt;

&lt;p&gt;This setting is configured at the organization level and applies to all admin users associated with that organization.&lt;/p&gt;</content><author><name></name></author><category term="customer" /><summary type="html">The IP Restrictions feature allows organization admins to restrict access to their organization based on IP address. By configuring an allowlist, you can ensure that only users connecting from approved IP addresses or CIDR ranges are able to access data within the organization.</summary></entry><entry><title type="html">New API version released V1.1.0</title><link href="https://docs.bugcrowd.com/changelog/api/api-version-1.1.0/" rel="alternate" type="text/html" title="New API version released V1.1.0" /><published>2026-05-05T00:00:00+00:00</published><updated>2026-05-05T00:00:00+00:00</updated><id>https://docs.bugcrowd.com/changelog/api/api-version-1.1.0</id><content type="html" xml:base="https://docs.bugcrowd.com/changelog/api/api-version-1.1.0/">&lt;p&gt;See the full &lt;a href=&quot;https://docs.bugcrowd.com/api/1.1.0/&quot;&gt;API Version 1.1.0 reference&lt;/a&gt; for request/response details.&lt;/p&gt;

&lt;h2 id=&quot;funding_pool-include-on-monetary-rewards&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;funding_pool&lt;/code&gt; include on monetary rewards&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;funding_pool&lt;/code&gt; as an includable relationship on the monetary reward endpoint.
Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include=funding_pool&lt;/code&gt; to retrieve the funding pool associated with a monetary reward in a single request.&lt;/p&gt;

&lt;h2 id=&quot;last_activity_feed_item_created_at-filter-on-the-submissions-index&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;last_activity_feed_item_created_at&lt;/code&gt; filter on the submissions index&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;filter[last_activity_feed_item_created_at]&lt;/code&gt; query parameter to the submissions index endpoint.
This allows filtering submissions by the timestamp of their last activity feed item.&lt;/p&gt;

&lt;h2 id=&quot;active_blocker-include-on-submissions&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_blocker&lt;/code&gt; include on submissions&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_blocker&lt;/code&gt; as an includable relationship on the submission endpoint.
Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include=active_blocker&lt;/code&gt; to retrieve the active blocker for a submission in a single request.&lt;/p&gt;

&lt;h2 id=&quot;active_researcher_request_response-include-on-submissions&quot;&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_researcher_request_response&lt;/code&gt; include on submissions&lt;/h2&gt;

&lt;p&gt;Added &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;active_researcher_request_response&lt;/code&gt; as an includable relationship on the submission endpoint.
Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;include=active_researcher_request_response&lt;/code&gt; to retrieve the active researcher request response for a submission in a single request.&lt;/p&gt;

&lt;h2 id=&quot;credential-bucket-endpoints&quot;&gt;Credential bucket endpoints&lt;/h2&gt;

&lt;p&gt;Added credential bucket endpoints.
Credential buckets allow programs to manage pools of credentials for researchers to use during testing.&lt;/p&gt;

&lt;h2 id=&quot;credential-endpoints&quot;&gt;Credential endpoints&lt;/h2&gt;

&lt;p&gt;Added credential endpoints.
Credentials represent individual login credentials within a credential bucket that can be assigned to researchers.&lt;/p&gt;

&lt;h2 id=&quot;post-submissionssearch-endpoint&quot;&gt;POST &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/submissions/search&lt;/code&gt; endpoint&lt;/h2&gt;

&lt;p&gt;Added a POST endpoint for searching submissions with a JSON request body.
Accepts filter, sort, page, include, and fields parameters in the body, avoiding URL length limitations for complex queries.&lt;/p&gt;</content><author><name></name></author><category term="api_webhook" /><summary type="html">See the full API Version 1.1.0 reference for request/response details.</summary></entry></feed>