Skip to content

SquashTM 15.X Release Notes

Xsquash4Jira: Adaptation to the New Jira Software Endpoints

Following the deprecation announcement published by Atlassian on May 1, 2026, Jira Software Cloud REST endpoints using random page access will be removed after November 1, 2026.

To anticipate this change, Xsquash4Jira no longer uses the /rest/agile/1.0/** endpoints. They have been replaced by their /rest/software/1.0/** equivalents, and the pagination logic has been adapted accordingly. It is now based on the isLast field.

Action Required Before November 1, 2026

Any instance still running SquashTM 13 or earlier and connected to Jira Cloud will see Xsquash4Jira synchronization stop working after November 1, 2026, once Atlassian removes the old endpoints.

An upgrade to SquashTM 15.0.0 (or at least 14.0.5) is strongly recommended before this date

SquashTM 15.0.0

Released on 26/08/2026

Evolutions

  • Administration:

    • Allow restriction of project renaming to administrators.
  • Artificial Intelligence:

    • Test case generation now supports adding test cases as contextual input.
    • Prompt configuration is available at project-level, allowing non administrator users to create and configure them for their project needs.
    • The new Artificial Intelligence Statistics screen allow administrators to supervise the AI usage on the instance. It surfaces adoption metrics, estimation of tokens usage as well as a detailed history of LLM calls. It provides customization and export capabilities.
    • Better handling of rich text field's images in test case generation.
    • Allow to create the target folder from the test case generation screen.
    • Added configurable context size and format guardrails for test case generation.
    • Allow to use Bearer token authentication for Azure OpenAI servers
  • Automation:

    • Indicate automatable test cases in execution plans based on automated test reference.
  • Execution:

    • Quality of life improvements in Sprints:
      • Better consistency between Requirement and Sprint Requirement views.
      • Better navigation from the Sprint's Requirements table to the corresponding Sprint Requirement views.
      • Rename confusing labels.
  • Redmine Bugtracker:

    • General improvements on performances.
  • Technical:

    • Update Spring Boot to version 4.0.6.
  • Transverse:

    • Store links to image attachments as relative links in rich text fields.
    • Give attachments UUIDs.
    • Better keyboard navigation inside navigation trees.

Corrections

Core

  • Administration:

    • Fix "No Data" popup triggered by browser autofill on the automation server Token field.
    • Disable "Add a template from the selected project" when the selection is not exactly one project.
    • Add inline validation error when a custom field default value exceeds 255 characters.
    • Fix missing error message when creating a user with a whitespace-only login.
    • Add email format validation:
      • when creating or editing a user ;
      • on user creation and modification endpoints.
    • Fix broken display of requirements and test cases after modifying a project's information list.
    • Fix custom fields not applied to entities created while the field is being added.
    • Fix custom fields being uneditable on test cases restored from the recycle bin.
    • Fix Copy button for personal API tokens not working on HTTP instances.
    • Update default profile descriptions to use gender-neutral language.
    • Fix duplicate profile creation allowed by trailing spaces in profile names.
    • Add length validation on the attachments whitelist to prevent errors on long values.
    • Fix default option checkbox unchecked when renaming a required custom field option.
    • Hide BDD step editing controls when the user lacks "Create" permission in the Action Words workspace.
    • 467 Display a clear error message when a user cannot be deactivated due to synchronization ownership.
    • Fix information list table not updating when the default value is renamed.
    • Fix SCM server type field being emptied when clicking "Add another".
    • Fix infinite spinner when accessing administration workspace URLs without authorization.
    • 112 Fix missing validation error for invalid numeric custom field default values.
    • Fix grid sort state not persisting after returning from a detail page in administration.
  • Artificial Intelligence:

    • Fix missing image format validation in AI test case generation context.
    • Fix rich text fields losing formatting when sent to the LLM during test case generation.
    • Prevent sending context items to the LLM when the selected prompt has no context wrapper.
    • Fix suggested test cases counter not resetting during AI generation reload.
    • Fix AI entity names not trimmed on creation and edit, allowing duplicates.
    • Display an explicit error when saving AI-generated test cases to a deleted folder.
    • Fix double scrollbar in the AI Chat folder selection modal on small screens.
    • Fix unsupported error when testing an AI server configuration with a non-existing URL.
  • Automation:

    • Fix blocking spinner on the automation server configuration page when the orchestrator is unreachable.
    • Improve automated execution parameter resolution by replacing recursive N+1 queries with a single bulk query.
    • Fix inability to delete:
      • a test automation server referenced by a test case in the recycle bin ;
      • an SCM server when a transmitted test case is in the recycle bin ;
      • an SCM repository when a transmitted test case is in the recycle bin.
    • 654 Fix automated test execution order following iteration order instead of test suite order.
    • Fix full page spinner when the orchestrator is unreachable on iteration or test suite pages.
    • Fix automation workspace table not refreshing after a test case status change.
  • Ergonomics:

    • Fix inconsistent and grammatically incorrect numeric operator labels in charts and search.
    • Fix semi-bold font weight not rendering correctly on Firefox.
    • Fix inconsistent grammar in the French drag-and-drop attachment area label.
    • Fix typos and missing translations in project template menu labels.
    • Fix images not displaying in requirement and test case printouts.
    • Fix tooltip alignment in the Sprint Requirements block.
    • Fix typos in the "Add high-level requirement" Premium dialog.
    • Update the browser page title from "Squash Test Management" to "SquashTM".
    • Fix bugtracker credential error messages persisting after switching bugtrackers in My Account.
    • Fix missing tooltip on the Restore button in the recycle bin.
    • Fix hyperlinks in rich text fields to always open in a new tab.
    • Fix block styling (rounded corners and gray borders) lost when enabling quick tests on requirement pages.
    • Fix French permission label to include "Dissocier" for test case-requirement association.
    • Fix misaligned option labels in the milestone duplication dialog.
    • Fix misalignment between editable text fields and confirm/cancel buttons.
    • Fix misalignment of "Expand all" and "Collapse all" buttons in the permission matrix.
    • Fix mismatched anchor and block names on the requirement execution plan page.
    • Fix action words menu incorrectly selected in the nav bar without an Ultimate license.
  • Executions:

    • Fix error when copying an iteration with test suites to another project.
    • 707 Fix test suite deletion failing when an automated test is referenced by a test case in the recycle bin.
    • Fix intermittent attachment list loading failure during test execution.
    • Fix flaky final status calculation for manual and automated executions.
    • Fix 500 error when filtering execution plan by mode with "Last executed items" scope.
    • Fix inconsistent delete button visibility in the execution history popup.
    • Fix error when adding an iteration with execution plan copy after a test case deletion.
    • Fix requirement deletion unavailable in the sprint requirement version table.
    • Fix DELETE_EXECUTION permission not being applied in sprints.
    • Fix duplicate execution error when two users execute the same test plan item concurrently.
    • Fix missing "TC_PROJECT_ID" column in simple and standard campaign CSV exports.
    • Fix missing time in the EXECUTION_DATE column of campaign export CSV files.
    • Fix "Search for requirements to associate" button not responding during test step modification from the execution popup.
    • 643 Fix Gherkin docstrings displayed in unreadable white font during manual execution.
    • 641 Fix "Add an iteration" button disabled in search when a milestone is set on the project.
    • Fix error when reordering campaigns using positional sorting in the execution workspace.
    • 489 Fix error when returning to execution after modifying a called test case with no dataset selected.
    • 486 Fix test suite status capsule not updating after a fastpass execution.
    • Fix execution status not updating on the test plan item search page.
    • 705 Fix the different names for the TC_NAME, IT_NAME, and IT_NUM columns in the standard campaign export.
  • Import:

    • Fix missing attachment links in test steps after a pivot import.
    • Fix HTTP 500 error when importing a test case with an invalid TC_STEP_IS_CALL_STEP value.
    • Fix Import button remaining enabled after simulation reports the file as invalid.
    • Fix Gherkin test case import failing with an error despite successful simulation.
    • Fix typo in requirement export column name: ATTACHEMENT is now ATTACHMENT.
    • Fix Xray project import failing when the export contains multiple linked issue types.
  • Performance:

    • Fix manual execution creation time scaling with test plan size.
    • Improve permanent node deletion performance in large trees.
    • Improve deletion performance by skipping unnecessary queries on empty working tables.
    • Improve orphan attachment cleanup query performance during deletion operations.
    • Improve requirement tree loading performance for users with many projects.
    • Improve Automation workspace grid loading performance on large instances.
    • Fix deletion of orphan failure details and their associated issues when cleaning old automated suites.
    • Improve performance when loading known issues linked to executions and quick tests.
    • 610 Improve automated execution deletion performance for large volumes.
    • Improve Automation workspace loading performance with large numbers of analyzed test cases.
    • Fix deadlock during concurrent iteration deletions.
    • 693 Fix performance regression for execution creation on large test plans via REST API.
  • Reporting:

    • Fix concurrency error when deleting a node in the reporting workspace.
    • Improve PDF and editable test case report generation performance.
    • Fix HTML entities decoded instead of displayed literally in test case report titles.
    • Fix qualitative progress report including requirements from projects outside the selected perimeter.
    • Fix editable reports failing to download when outsourced image attachments are invalid.
    • 662 Fix missing requirement IDs in execution steps of custom exports.
    • 658 Fix folder copy/paste in Reporting workspace only pasting the parent folder without its content.
    • Fix broken table of contents formatting in PDF test case reports.
    • Fix incorrect item scope filter in search when clicking on iteration dashboard charts.
    • Fix corrupted DOCX campaign or iteration report when a defect status contains a special character.
    • Fix error when downloading a custom export with an iteration as perimeter.
    • Fix duplicate attributes in custom exports after changing the perimeter.
    • Fix incorrect default file format for the requirement list in Qualitative progress report.
    • Fix editable test case report generation failing when too many test cases are selected.
    • Fix the cumulative progress chart not displaying correctly.
    • Fix child options not deselected when unchecking "Print test steps" in test case reports.
    • Fix inconsistent test case order in PDF reports when selecting multiple nodes.
    • Fix English translation errors in report labels for statuses and requirement workflows.
    • Fix incorrect alphabetical order in editable requirement report summaries.
    • Add the Assignee attribute to custom exports.
  • Requirements:

    • Fix inconsistent last execution display for test cases linked to high-level requirements.
    • Fix requirement search with custom field criteria failing on subsequent searches.
    • 454 Fix existing link between two requirements not being pre-filled in the requirement modification dialog.
  • Security:

    • Fix HTML characters not escaped in the user picker.
    • Fix path traversal vulnerability in import-log download endpoints.
    • Fix login attempts by deactivated users not recorded in Connection History.
    • Fix unauthorized users being able to delete attachments by bypassing permission checks.
    • 105 Fix LDAP users unable to access the "My Account" page in certain configurations.
    • Fix missing or incorrect permission and ACL checks on various endpoints and actions:
      • Campaign, iteration, and test suite listing.
      • Test suite and folder creation in the campaign tree.
      • Chart preview (ACL filter bypass with an empty scope).
      • Milestone mass-modification search.
      • Execution and exploratory-session read (READ).
      • Execution step comment and automation flag (EXECUTE).
      • Known-issue read, allowing cross-project disclosure (ACL).
      • Action-word view and grid read.
      • Project AI configuration (MANAGE_PROJECT).
      • Pivot import file pre-check (IMPORT).
      • Custom export available custom field columns, now restricted to the caller's readable projects.
      • Report template download (admin role).
      • Action-word copy simulation (CREATE).
      • Requirement read and validation statistics.
      • Test automation project endpoints.
      • Test automation script association.
      • Quick test feature administration (admin role).
      • Manual execution launch by a Test Runner, now restricted to assigned executions.
      • Test case statistics (ACL filter bypass on the computed scope).
      • Scripted test case validation.
      • Keyword step project comparison.
      • Test case datasets read.
      • Test case recycle bin content listing.
      • Test case parameter description editing (WRITE).
      • Scripted test case script editing (WRITE).
      • Project automation environment tags modification.
      • Sprint req version status read.
      • Adding test plan items with datasets to a sprint test plan.
      • Reordering test plan items.
      • Entity creation via clipboard paste by Guest users, across all workspaces.
      • Deletion-simulation endpoints, across all workspaces.
      • Sprint status change, which required "Associate" permission instead of "Modify".
    • Fix OIDC issues:
      • Login case sensitivity causing user data retrieval failure when case-insensitive login is enabled.
      • Authentication failure page crashing instead of displaying the error message.
    • Fix CVE vulnerabilities:
      • CVE-2026-39363 by upgrading Vite dependency to version 7.3.2.
      • Prototype pollution vulnerability (CVE-2023-26136) by removing outdated tough-cookie dependency.
      • CVE-2026-41901 (critical Thymeleaf SSTI) by upgrading dependencies.
      • CVE-2026-40477 and CVE-2026-40478 (critical Thymeleaf SSTI sandbox bypass).
      • CVE-2025-10492 by upgrading JasperReports library to version 7.
      • CVE-2026-22732 (Spring Security HTTP header omission vulnerability) by upgrading Spring Security.
  • Technical:

    • Add database repair scripts to fix corrupted relationship closure tables during version upgrade.
    • Fix migration failure when no test cases are present in the migrated project.
  • Test cases:

    • Fix auto-computed importance incorrectly lowered when deleting a linked requirement.
    • Fix test case export failure on large libraries due to query parameter limit.
    • Fix missing HTML escaping in the action word deletion confirmation popup.
    • Fix incorrect default filename pattern for test case exports.
    • 644 Fix Gherkin autocomplete and insertion not working when the script language is set to English.
    • Fix expand/collapse icon showing on empty test case folder after deleting its content.
    • Fix Enter key not submitting dataset creation or modification dialogs.
    • Fix incorrect duplicate warning when moving an action word between projects.
    • Fix "Sessions" anchor not persisting when navigating to an exploratory test case.
  • Transverse:

    • Display an error message when moving a folder to a location containing a same-named folder.
    • Fix underscore and percentage characters treated as wildcards in search bars.

Plugins

  • API:

    • REST API:

      • Fix REST API allowing attachment deletion across entities without proper permission verification.
      • Fix typos and inconsistencies in the admin REST API user documentation.
      • Fix attachment upload failure in automated suite API when file repository is enabled.
      • Remove the unnecessary navigation confirmation when accessing the REST API documentation.
      • 656 Fix 500 error when retrieving externalized attachment content via REST API.
      • Fix AI server options field returned as string instead of JSON object in REST API responses.
      • 649 Fix error 500 when updating execution step status via the API after an automated execution.
      • Fix NullPointerException on GET /exploratory-sessions/{id} when the session belongs to a sprint.
      • Fix campaign, sprint, and sprint group creation via REST API when using a project ID as parent.
      • Allow infrastructure admins to access the license info endpoint in cloud mode.
      • Fix license info endpoint returning 401 Unauthorized when cloud mode is enabled.
      • Fix duplicate formats not being deduplicated in AI server supported_formats.
      • Allow clearing the context_wrapper_template field via the PATCH prompts endpoint.
      • Fix incorrect folder hierarchy returned by the /requirement-folders/tree/{ids} endpoint.
      • Fix incorrect folder hierarchy in the test case folders tree API endpoint.
      • Update API documentation to specify that the executor endpoint only works with Jenkins.
      • Improve performance of test plan retrieval for iterations, suites, and sprints.
      • 13 Fix folder tree endpoints incorrectly returning child folders as root folders.
      • Fix missing library IDs in the response of the GET /projects/{id} endpoint.
      • Add an endpoint to retrieve the executions of a test case.
  • Authentication:

    • SAML:

      • Fix SAML login failure when the assertion contains a SubjectLocality element.
  • Automation:

    • Jira Automation Workflow:

      • Add permission check on the plugin configuration deletion endpoint.
      • Add permission checks on Jira configuration endpoints querying the remote server.
      • Allow creating a new Jira ticket when retransmitting a test case whose previous ticket reached final status.
  • Bugtracker:

    • Azure DevOps Bugtracker:

      • Fix work item association failing when the Azure DevOps project name contains spaces.
    • GitLab Bugtracker:

      • Fix misplaced tooltip on the issue form "Search by" label.
    • Jira Cloud Bugtracker:

      • Fix missing validation errors for required checkbox and two-level list fields when reporting a Jira issue.
    • Redmine Bugtracker:

      • Fix error in cache construction for Redmine bugtracker.
      • Fix issue reporting failure when a Redmine tracker contains an integer field.
      • Fix integer custom fields accepting non-integer input when reporting a Redmine issue.
      • Fix newly linked Redmine projects not appearing in the server cache configuration.
      • Limit instance freeze duration when saving credentials for an unreachable Redmine server.
    • Tuleap Bugtracker:

      • Fix squashtm.bugtracker.timeout property not being honored.
  • SquashTM Orchestrator:

    • 229 Fix or update CVE vulnerabilities:
      • critical libssh2 vulnerability (CVE-2026-55200) in orchestrator Docker image ;
      • critical authentication bypass vulnerability in gnutls (CVE-2026-42010) ;
      • CVE-2026-33845 in GnuTLS (denial of service via DTLS zero-length fragment) ;
      • CVE-2025-13836 in orchestrator Docker image by updating Python base image ;
      • CVE-2025-13836 in orchestrator all-in-one image by using a slim base image.
    • 2 195 40 Remove embedded SSH host private keys from:
      • automation runner Docker image ;
      • Maven runner Docker image ;
      • Robot Framework runner Docker image.
  • Syncing Requirements:

    • Redmine Requirements:

      • Fix decimal number custom fields not synchronizing from Redmine requirements.
    • Xsquash4GitLab:

      • Add missing permission checks on execution plan wizard read endpoints.
      • Add a retry mechanism for webhook processing when GitLab returns HTTP 429 rate-limit errors.
      • Add permission check on the project value-mappings read endpoint.
      • Add permission check on the GitLab perimeter info endpoint.
      • Add permission check on GitLab sync simulation endpoints.
    • Xsquash4Jira:

      • 708 Fix error when retrieving the 'Parent' field from Jira Cloud tickets.
      • 703 Fix Jira Datacenter issue page failing to display when SquashTM is unreachable.
      • Fix missing permission check on:
        • execution plan server list and JQL search endpoints.
        • execution plan designer campaign resolution endpoint.
        • campaign iteration metadata endpoint in execution plan designer.
        • credential status endpoint.
      • Fix plugin configuration panel accessible to users without project management permission.
      • Fix synchronization importing subtasks outside the configured JQL scope.
      • Display an error message when invalid credentials are entered for a Jira Cloud server.
      • 657 Fix filter and JQL synchronizations incorrectly reporting success when the server token is expired.
      • Fix synchronized tickets not moving to the correct sprint folder when relocated outside the synchronized folder.
      • Fix duplicate version display in the Xsquash4Jira execution plan designer wizard.
      • 593 Fix synchronization error when a Jira issue is added during an ongoing sync.
      • 14 Fix error when querying project synchronisations with multiple sync plugins configured.

Compatibility with third-party software

Ticket management

SoftwareVersion
GitLab Cloud19.3.0-pre
GitLab Server17.7 and 18.10
Jira Cloud1001
Jira DataCenter10.4.1

Anomaly management

SoftwareVersion
Azure DevOps ServicesDev20.M272.1
Azure DevOps Server2022.1
Bugzilla5.0.6
GitLab Cloud19.3.0-pre
GitLab Server17.7
Jira Cloud10.01
Jira DataCenter10.4.1
Mantis2.25.3
Redmine6.0.6
Tuleap17.1.99

Automation

Testing technologiesVersion
Agilitest 💎2.3.0
Cucumber JVM7.0.0
Cucumber JVM4.2.6
Cypress12.12.0
JUnit5.3.2
JUnit4.12
Katalon 💎8.2.0
Playwright1.43.1
Postman8.12.1
Ranorex 💎9.5
Robot Framework6.1.1
SKF1.14.0
SoapUI5.6.0
UFT 💎15.0.2