All release notes

v3.4.1: Framework sources you can trust and move

Platform

Published Aug 22, 2026

Mixedv3.4.1

Framework updates now use a retained source of truth
Benthic now keeps the exact OSCAL source and compiled relationships behind a
framework installation. Updates no longer depend on whichever framework package
happens to be running at the time, making results more repeatable and easier to
explain.
Portable playbooks keep their meaning
Built-in frameworks, portable playbooks, profiles, and program levels now pass
through the same project-basis model. Their controls and relationships retain
stable source identities as content moves between projects or advances to a new
version.
Migration decisions are explicit
New bounded audit tools classify existing framework bindings and identify cases
whose original source cannot yet be proven. Those cases remain visible for
review instead of being silently inferred from today's package.
Also improved

  • Canonical OSCAL 1.2.2 catalogs can be retained from JSON or XML sources.

  • Framework and playbook updates share one dependency-ordered planning path.

  • Large fleet audits use stable, resumable pagination for safer operations.

  • Production origin access and release provenance checks are more tightly

enforced.

Questions or feedback? Reply on this update and tell us where the workflow still
needs work.

v3.4.1: Framework sources you can trust and move