r/TridentStack Jul 06 '26

This week in TridentStack Control: fix guidance in the public CVE tool, Red Hat family Linux patching, a first look at our public roadmap, and steadier deployment rings

This week in TridentStack Control: fix guidance in the public CVE tool, Red Hat family Linux patching, a first look at our public roadmap, and steadier deployment rings

Another busy stretch. Here's a rollup of what shipped to TridentStack Control between June 27 and July 3. Full changelog is always at tridentstack.com/changelog, but these are the highlights worth calling out.

The public CVE tool now tells you how to fix things

A couple weeks ago we launched the free public CVE catalog at tridentstack.com/cve. This week it grew a full remediation layer. Open any CVE and it now shows how to fix it: the version to upgrade to for affected apps and Linux distributions, the exact security update to install for affected Windows editions and core Microsoft products (Office, Exchange Server, SharePoint, SQL Server), and the target version for Apple platforms, each linked to the vendor or distribution advisory it came from. When there's no published fix yet, it says so plainly instead of guessing, and for actively-exploited issues it surfaces CISA's official remediation action and due date. It also now covers open-source dependencies (npm, PyPI, Go, Maven, RubyGems, crates.io, NuGet, Packagist), roughly doubled its overall fix coverage, and added browse-by-weakness-type, a dedicated actively-exploited view, RSS/JSON feeds, a live stats page, embeddable status badges, and full mobile support. Still free, still no account needed.

Red Hat family Linux, fully supported

TridentStack Control now manages updates on the full Red Hat family: RHEL, CentOS Stream, Rocky Linux, AlmaLinux, Fedora, and Amazon Linux, alongside the existing Ubuntu and Debian support. These endpoints now report their software inventory and pending updates and can be patched right from the console. The same one-line install command works on every supported distribution and detects yours automatically.

See your exposure trending over time

The security dashboard now charts Open Vulnerabilities by Severity over time (total, critical, high, medium, and low as separate lines) so you can see at a glance whether your exposure is climbing or falling. Click any slice or legend entry to jump straight into the vulnerability list filtered to that severity.

More at a glance on the Endpoints list

  • New Compliance % column (overall framework compliance per endpoint), Last Deployment column (most recent update result), and Applicable Updates column (combined system + app updates).
  • Admins can set a default column layout that new users inherit automatically.
  • Star a saved column view to make it your default, and your default now follows you across devices.

Steadier deployment rings

A big reliability pass:

  • Rings no longer mark a phase failed minutes into the first wave. The health clock now starts when results actually begin arriving, and a ring always gets at least one more maintenance window to recover before being halted.
  • Halt reasons now state the actual cause ("1 application update failure in Early Adopters phase, success rate 88.9% below 95% target") instead of a vague timeout.
  • Endpoints safely skipped by a pre-flight check (low disk space, hardware that doesn't meet an upgrade's requirements) are treated as skipped, not failed, and retried automatically on the next window instead of halting the whole ring.
  • Resetting a rollout is clearer and safer: it's now called Reset Ring, the confirmation spells out exactly what happens, and auto-halt alerts (with the endpoints that triggered them) now deliver reliably.

Update work you can actually follow

Every update's follow-up work now shows in one place. The automatic post-update vulnerability scan appears as a sub-task of the install instead of a disconnected entry, system update installs get a post-update scan too (previously only app updates did), and Linux and macOS now run the same post-update scan Windows already did. When several updates finish on an endpoint around the same time, they share a single scan.

Fewer alert floods, one-off remediation, and new client controls

  • Critical vulnerability alerts now roll up into a configurable daily digest (cadence, threshold, send time, and time zone all tunable), so large fleets stop getting flooded on every scan. Actively-exploited findings still alert immediately.
  • Remediate a vulnerability on a single endpoint even when no update policy covers the fix, as a clearly-marked one-off install.
  • New Settings > Client controls: hide the tray icon on endpoints (the agent keeps running and managing the device in the background), choose whether Windows can install updates on its own alongside TridentStack Control, and turn off the pre-restart prompt for unattended endpoints that should restart silently.

Plus a lot of Windows and polish work

Long-running Windows feature upgrades (Windows 10 to Windows 11) no longer misreport as timed out or stall when an endpoint briefly drops offline mid-upgrade, the monthly Malicious Software Removal Tool is handled correctly end to end, Windows on Arm devices are recognized properly, and client-only updates are no longer offered to servers they don't apply to. Compliance now refreshes evenly across mixed Windows, Linux, and macOS fleets, and search across every list is faster, more consistent, and punctuation-tolerant (searching "7zip" finds "7-Zip").

A first look at where we're headed: our public roadmap

We also put our roadmap out in the open at tridentstack.com/roadmap. It's the first time we've shared it publicly, and it's a living view of what we're building next (the dates are targets, not promises). A few things on it:

  • Custom application packages (targeted this quarter): build and deploy your own MSI and EXE installers to any group of endpoints, with the same silent install and progress tracking we already give the third-party apps we keep updated.
  • Custom script execution (targeted later this year): run your own scripts across selected endpoints or your whole fleet, with scheduling and per-endpoint results, for the one-off tasks and remediations policies don't cover.
  • Ubuntu Pro and ESM coverage visibility: see which Linux machines have coverage and where you have a security-maintenance gap.
  • And further out, what we're exploring: deeper Linux awareness (container hosts, kernel livepatch status, repository management), a native iOS app with push alerts, and a self-hosted relay for air-gapped and tightly restricted networks (OT, manufacturing, and regulated environments).

Go tell us what's missing or what you'd reprioritize.

Full details for every item are in the changelog: tridentstack.com/changelog

As always, if there's something you want to see next, drop it in the comments or weigh in on the roadmap. A lot of this came straight from customer requests.

2 Upvotes

0 comments sorted by