What We're Working on for NPM (Updated: February 8, 2021)

Following the Sunburst security incident, SolarWinds remains committed to the safety and security of our products and technology. Throughout 2021, we will prioritize security enhancements ahead of feature development to maximize customer safety and ensure confidence in SolarWinds and our products.  

Items currently being considered include, but are not limited to:

  • Vulnerability fixes identified by third-party scanning tools or recent product penetration tests (pentesting)
  • Documentation of least privileges for Orion Platform operation and monitoring including Orion agents
  • Validation of CIS IIS and SQL Server best practices
  • Secure settings by default with user control
  • Removal of any code unsupported by Microsoft
Anonymous
  • Is there a new WWWO post available for NPM?

  • All this security is great and thank you for the your efforts.
    But when will we see feature requests and product "updates"? Update = Issue Fixes
    There are SO MANY issues with the Great and Powerful Orion Maps that they are of VERY little use.  And when there is an issue with Network Atlas support states that Network Atlas is to deprecated and therefore there is no chance of help.
    From reading the statement above "Throughout 2021, we will prioritize security enhancements ahead of feature development to maximize customer safety and ensure confidence in SolarWinds and our products", it sounds as though we can not hope to see any enhancements until 2022.
    There are SO MANY FRETURE requests that are years old that I wonder why we, as users, even bother with them.  May be next year.

  • In the past, questions and feature requests for the Orion platform in general have been steered towards the NPM module. Perhaps this may be a good time to create a WWWO post (and forum) for the Orion platform?

  • i need to start NPM from basics

  • While this is great to add a security focus going forward, where are the feature enhancements and stability improvements for the 6 months of dev time between 2020.2 released and the hack release? At this point, it sounds like we're going to go a complete year without a new feature enhancements. A great example is that is has been 9 years since reoccurring maintenance windows within the platform has been requested...