Enhancement
Scan Duration Estimation
You can now see an estimated scan duration before starting a scan. The estimate is based on your project’s Entry Points, selected tests, and past scan history. We also moved the scheduling section to the top of the tab to make it easier to access.
This helps you plan ahead, understand how long a scan is likely to take, and avoid unnecessary surprises - making the scan setup process smoother and more predictable.
Authentication Objects Now Visible in Scan Configuration
You can now see which Authentication Object (AO) is linked to each Entrypoint directly inside the Scan Configuration page, as well as the Project, Scan, and Discovery pages. Clearly shows either the assigned AO name or a simple “No authentication object is assigned.” You can also filter Entrypoints by whether they have an AO or not for better data management.
This improvement gives you a clearer view of which Entrypoints are authenticated before running a scan. It reduces confusion, keeps both pages aligned, and helps you quickly spot missing authentication setups, so scans run more smoothly.
WebGRPC Support
We’ve added full support for WebGRPC in our DAST engine. From now on, any target using WebGRPC (GRPC over HTTP/1.1 or HTTP/2) will be scanned automatically. There’s no need to upload GRPC schemas or proto files - Bright now detects, decodes, and parses everything directly from the HAR or crawler.
This makes scanning modern WebGRPC-based applications faster and simpler. You get full coverage without extra setup, manual uploads, or configuration work.
Updated Role Scopes for Organization & Member Management
We updated how organization-level scopes work to make permissions clearer and more predictable. Users will now see only the parts of the Organization settings that match their assigned scopes, and admins can manage members and groups more reliably.
This change makes access control easier to understand, reduces confusion, and helps large teams manage users and groups with confidence.
Scope Overview:
- org:readgives access to the Organization tab and general org details, but does not grant visibility into members.
- org.memberships:read allows users to see only the members who share a mutual group with them (excluding “Everyone”). Together with org:read, it enables opening the Organization tab and viewing the filtered member list.
- org.memberships:manage allows managing group memberships, including adding, editing, and removing members from groups.
- groups:manage allows creating, editing, and deleting groups, but does not control member visibility.
- groups:admin provides administrative control over groups only and should not be required for viewing members.
Improved Deletion Behavior for Entry Points and Issues
We improved the behavior of deleting Entry Points to ensure consistency. From now on, when an Entry Point is removed, all Issues linked to it are automatically removed as well. This keeps your project data clean and free from outdated or disconnected information.
This update helps maintain accurate vulnerability data, reduces noise from irrelevant Issues, and gives you a clearer, more trustworthy view of your project’s security status.





















