Contentctl

Latest version: v5.1.0

Safety actively analyzes 715032 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 4 of 10

4.3.4

This PR includes extended support for ensuring that the appropriate Risk and Observable objects are created. See the PR linked below for more details.
There are also some small validation fixes around validating MITRE ID formats.

What's Changed
* Abstract Commonly Used Annotated Type Definitions by pyth0n1c in https://github.com/splunk/contentctl/pull/271
* Update setuptools requirement from >=69.5.1,<74.0.0 to >=69.5.1,<75.0.0 by dependabot in https://github.com/splunk/contentctl/pull/270
* Enabling risk/observable matching by cmcginley-splunk in https://github.com/splunk/contentctl/pull/241
* Update pyproject.toml by pyth0n1c in https://github.com/splunk/contentctl/pull/281


**Full Changelog**: https://github.com/splunk/contentctl/compare/v4.3.3...v4.3.4

4.3.3

The `action.correlationsearch.metadata` field was updated to include an additional value called `publish_date`, a timestamp float representing when a detection was published.
Additionally, some cleanup was done around testing and the test_results/summary.yml was improved significantly to support better test results/tracking.
Finally, if searches use Baselines but have not been marked manual_test, they will throw runtime Exceptions during testing until Baselines are officially supported in the testing workflow.

What's Changed
* add publish_date field by pyth0n1c in https://github.com/splunk/contentctl/pull/239
* Responses to Comments by pyth0n1c in https://github.com/splunk/contentctl/pull/260
* Expanding coverage and other metrics in summary.yml by cmcginley-splunk in https://github.com/splunk/contentctl/pull/257


**Full Changelog**: https://github.com/splunk/contentctl/compare/v4.3.2...v4.3.3

4.3.2

What's Changed
* add support for the entire mitre group metadata by pyth0n1c in https://github.com/splunk/contentctl/pull/253


**Full Changelog**: https://github.com/splunk/contentctl/compare/v4.3.1...v4.3.2

4.3.1

Improve checking against observables. These changes ensure that Threat Objects and Risk Objects are created correctly.

What's Changed
* Threat objects by ljstella in https://github.com/splunk/contentctl/pull/234
* New observable role enum by ljstella in https://github.com/splunk/contentctl/pull/243
* Update setuptools requirement from >=69.5.1,<73.0.0 to >=69.5.1,<74.0.0 by dependabot in https://github.com/splunk/contentctl/pull/245


**Full Changelog**: https://github.com/splunk/contentctl/compare/v4.3.0...v4.3.1

4.3.0

This change removes code and references to SSA as they are not applicable to external users.
What's Changed
* Update readme by pyth0n1c in https://github.com/splunk/contentctl/pull/244
* Remove SSA specific code by P4T12ICK in https://github.com/splunk/contentctl/pull/219


**Full Changelog**: https://github.com/splunk/contentctl/compare/v4.2.5...v4.3.0

4.2.5

A number of small improvements from internal and community PRs. See the "What's Changed" below for details.

What's Changed
* Add a launcher to contentctl.py to allow easier debugging and launchi… by Res260 in https://github.com/splunk/contentctl/pull/212
* Update attackcti requirement from ^0.3.7 to >=0.3.7,<0.5.0 by dependabot in https://github.com/splunk/contentctl/pull/214
* Update on naming for the repo readme vs app readme by pyth0n1c in https://github.com/splunk/contentctl/pull/235
* Hotfix: Bumping integration testing timeout to compensate for recent bugfix by cmcginley-splunk in https://github.com/splunk/contentctl/pull/240


**Full Changelog**: https://github.com/splunk/contentctl/compare/v4.2.4...v4.2.5

Page 4 of 10

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.