chore: update changelog August 11-14 CLI and Platform releases - #362
Open
mintlify[bot] wants to merge 1 commit into
Open
chore: update changelog August 11-14 CLI and Platform releases#362mintlify[bot] wants to merge 1 commit into
mintlify[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
Preview deployment for your docs. Learn more about Mintlify Previews.
|
Contributor
|
Claude finished @mintlify[bot]'s task in 1m 10s —— View job Review of PR #362 — Changelog: August 11–14
Findings
|
| Category | Count |
|---|---|
| Critical | 0 |
| Improvement | 2 |
| Suggestion | 0 |
Overall: Clean changelog addition. Structure, <Update> format, chronological ordering, and internal link (/getting_started/attestations — verified) all match existing conventions. The only issues are two British spellings that should be American per CLAUDE.md.
|
|
||
| ## New features | ||
|
|
||
| - **Custom attestation summaries** — [custom attestation types](/getting_started/attestations) can now define a `summary` list of JQ expressions that extract key values (for example `Critical`, `Tool`) from the payload. The attestation drawer renders these as labelled rows instead of only raw JSON, matching the built-in Sonar, Snyk, and JUnit types. Summaries are versioned with the type, so schema changes create a new version. Array payloads render one summary group per element. |
Contributor
There was a problem hiding this comment.
Improvement — American spelling (CLAUDE.md): "labelled" → "labeled"
Suggested change
| - **Custom attestation summaries** — [custom attestation types](/getting_started/attestations) can now define a `summary` list of JQ expressions that extract key values (for example `Critical`, `Tool`) from the payload. The attestation drawer renders these as labelled rows instead of only raw JSON, matching the built-in Sonar, Snyk, and JUnit types. Summaries are versioned with the type, so schema changes create a new version. Array payloads render one summary group per element. | |
| - **Custom attestation summaries** — [custom attestation types](/getting_started/attestations) can now define a `summary` list of JQ expressions that extract key values (for example `Critical`, `Tool`) from the payload. The attestation drawer renders these as labeled rows instead of only raw JSON, matching the built-in Sonar, Snyk, and JUnit types. Summaries are versioned with the type, so schema changes create a new version. Array payloads render one summary group per element. |
| ## Bug fixes | ||
|
|
||
| - **Faster webhook saves** — the SSRF guard on webhook URLs no longer performs a blocking DNS lookup while saving an action. A slow resolver can no longer stall the save (or time out the request). | ||
| - **Notification emails and trail events hardened against injected HTML** — user-controlled names and descriptions in notification emails and trail event descriptions are now HTML-escaped when rendered, closing a defence-in-depth gap on top of existing input validation. |
Contributor
There was a problem hiding this comment.
Improvement — American spelling (CLAUDE.md): "defence" → "defense"
Suggested change
| - **Notification emails and trail events hardened against injected HTML** — user-controlled names and descriptions in notification emails and trail event descriptions are now HTML-escaped when rendered, closing a defence-in-depth gap on top of existing input validation. | |
| - **Notification emails and trail events hardened against injected HTML** — user-controlled names and descriptions in notification emails and trail event descriptions are now HTML-escaped when rendered, closing a defense-in-depth gap on top of existing input validation. |
mbevc1
reviewed
Aug 17, 2026
|
|
||
| ## Updates | ||
|
|
||
| - **SCIM webhook status handling** — a Descope SCIM payload whose status is neither `enabled` nor `disabled` (for example `invited`) is now rejected with an explicit error instead of silently doing nothing. Tenant membership is read from the loaded Descope user, so it always follows authoritative IdP state. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add changelog entries for the CLI v2.36.6 release and the four Platform releases tagged between August 10-14, 2026.
Changes
/api/v2/flows/{org}response.No new tags were found on
kosli-dev/terraform-provider-kosliin the scope window.