diff --git a/changelog/index.mdx b/changelog/index.mdx index c5eacc9..09f5db1 100644 --- a/changelog/index.mdx +++ b/changelog/index.mdx @@ -4,6 +4,47 @@ description: "Release notes for Kosli products." rss: true --- + + +## Updates + +- **SCIM role changes sync from Descope** — SCIM webhooks that carry a role or group change without a status field are no longer ignored. A user's Kosli membership is reconciled from Descope on every `SCIMUserModified` event, so a role change (for example member → admin) or the removal of a role now applies immediately. +- **React pages redirect to login on session timeout** — Controls, Repos, Environments, and Audit Log now send you to the login page (with `next` set to where you were) when the session expires, instead of leaving the page with a generic error. +- **Unmatched `/api/*` returns JSON 404** — a request to a non-existent `/api/*` path now returns a JSON `404` instead of redirecting to the HTML login page, so API clients see a proper error. + + + + + +## Bug fixes + +- **Login email field focused on load** — the email input on the login and sign-in pages now receives focus automatically, so you can start typing straight away. +- **No more double-login inside off-canvas panels** — when a session expired while an off-canvas panel was open, the login page could get swapped into the panel instead of taking over the tab. Auth redirects from htmx requests now navigate the whole tab. + + + + + +## Updates + +- **Richer override attestation view** — override attestations now render a dedicated summary showing the reason, the original attestation's type and status, and a link to the overridden attestation, instead of the raw JSON payload. + +## Bug fixes + +- **Trail-by-artifact lookups no longer fail with tag filters** — `GET /api/v2/trails/{org}` filtered by fingerprint and `flow_tag` could return a 500 on large orgs because the database ran out of memory ordering the query. The fingerprint is now matched before flow filters, so these lookups return normally. + + + + + +## Bug fixes + +- **`kosli attest` no longer fails on container-produced attachments** — passing two or more `--attachments` paths could abort with `chown ...: operation not permitted` when an attachment (for example lint, test, or coverage output) had been written by a Docker container running as a different user. The CLI no longer tries to preserve file ownership when staging attachments for upload. A genuine copy error now also names the evidence path you passed rather than an internal temp directory. See the [`kosli attest` reference](/client_reference/kosli_attest_artifact) for usage. + +[View on GitHub](https://github.com/kosli-dev/cli/releases/tag/v2.36.4) + + + ## Updates