Release notes for Canopy 3.14

Follow the Upgrading steps when upgrading.

3.14.0 (2026-10-01)

Canopy 3.14 expands methodology workflows with a redesigned work page, custom fields on methodology items, and XLSX and JSON import and export. It also adds custom fields on reports, support for Nuclei and ZAP imports, and improvements to embedded image handling.

Message sending from the UI now enforces the message template, removing the need for additional permission checks that previously prevented certain users from evaluating message templates.

Valkey replaces RabbitMQ as the preferred broker. See Celery broker changes.

OIDC discovery simplifies single sign-on configuration.

Database migrations

Warning

Plan for a longer maintenance window. This release contains many database migrations, and Canopy will be unavailable while they run.

Migrations will move pasted images into files and process approximately 500 images and 500 MB per minute on fast hardware.

Migrations for small installations (fewer than 100 phases) should take a few minutes, while those for large installations (more than 2,000 phases) might take hours. The time required depends heavily on hardware and database performance.

Celery broker changes

Valkey (a Redis fork) is now Canopy’s preferred Celery message broker, in place of RabbitMQ. Existing installations keep their current broker, and RabbitMQ remains supported. To switch, run canopy-setup valkey, which configures Valkey. See Celery message broker.

Epics

  • [CAN-4081] Expand security tool support (Nuclei and ZAP)

  • [CAN-4095] Extract images from remaining Rich Text fields into files

  • [CAN-4122] Message template evaluation permissions

  • [CAN-4149] Report Custom fields

  • [CAN-4157] Add REPORT_DISTRIBUTE activity entry support

  • [CAN-4160] Valkey support

  • [CAN-4179] Questionnaire-ready methodologies

Tasks

  • [CAN-3567] Migrate celery beat db/state to DB

  • [CAN-4113] Expand CSP/SameSite and related settings

Bugs

  • [CAN-4047] Images in TinyMCE fields are downloaded from File Uploads as .txt

  • [CAN-4082] Rich Text content cut off with a lot of data (pasted images)

  • [CAN-4112] Admin Users and Skills password change not functioning

  • [CAN-4128] Health endpoint responses are not shown in the top bar of the UI

  • [CAN-4145] XML mapping generation creates invalid asset_asset element when custom fields are enabled on assets

  • [CAN-4206] Template Methodology item <-> Template Finding linking list shows draft entries

  • [CAN-4209] pci_status should default to empty string

Improvements

  • [CAN-4123] Ability to disable message templates

  • [CAN-4133] Prune outdated permission graph nodes/links

  • [CAN-4187] Expose custom field descriptions

  • [CAN-4193] Enable autoescaping in html based jinja message templates

  • [CAN-4208] Add OIDC discovery endpoint support

Older releases