Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions changelog/index.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,47 @@ description: "Release notes for Kosli products."
rss: true
---

<Update label="August 7, 2026" description="" tags={["Platform"]}>

## Updates

- **SCIM role changes sync from Descope** — SCIM webhooks that carry a role or group change without a status field are no longer ignored. A user's Kosli membership is reconciled from Descope on every `SCIMUserModified` event, so a role change (for example member → admin) or the removal of a role now applies immediately.
- **React pages redirect to login on session timeout** — Controls, Repos, Environments, and Audit Log now send you to the login page (with `next` set to where you were) when the session expires, instead of leaving the page with a generic error.
- **Unmatched `/api/*` returns JSON 404** — a request to a non-existent `/api/*` path now returns a JSON `404` instead of redirecting to the HTML login page, so API clients see a proper error.

</Update>

<Update label="August 5, 2026" description="" tags={["Platform"]}>

## Bug fixes

- **Login email field focused on load** — the email input on the login and sign-in pages now receives focus automatically, so you can start typing straight away.
- **No more double-login inside off-canvas panels** — when a session expired while an off-canvas panel was open, the login page could get swapped into the panel instead of taking over the tab. Auth redirects from htmx requests now navigate the whole tab.

</Update>

<Update label="August 4, 2026" description="" tags={["Platform"]}>

## Updates

- **Richer override attestation view** — override attestations now render a dedicated summary showing the reason, the original attestation's type and status, and a link to the overridden attestation, instead of the raw JSON payload.

## Bug fixes

- **Trail-by-artifact lookups no longer fail with tag filters** — `GET /api/v2/trails/{org}` filtered by fingerprint and `flow_tag` could return a 500 on large orgs because the database ran out of memory ordering the query. The fingerprint is now matched before flow filters, so these lookups return normally.

</Update>

<Update label="August 3, 2026" description="v2.36.4" tags={["CLI"]}>

## Bug fixes

- **`kosli attest` no longer fails on container-produced attachments** — passing two or more `--attachments` paths could abort with `chown ...: operation not permitted` when an attachment (for example lint, test, or coverage output) had been written by a Docker container running as a different user. The CLI no longer tries to preserve file ownership when staging attachments for upload. A genuine copy error now also names the evidence path you passed rather than an internal temp directory. See the [`kosli attest` reference](/client_reference/kosli_attest_artifact) for usage.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: The link text says `kosli attest` reference but points to the kosli_attest_artifact page. Consider updating the text to match the actual target:

Suggested change
- **`kosli attest` no longer fails on container-produced attachments** — passing two or more `--attachments` paths could abort with `chown ...: operation not permitted` when an attachment (for example lint, test, or coverage output) had been written by a Docker container running as a different user. The CLI no longer tries to preserve file ownership when staging attachments for upload. A genuine copy error now also names the evidence path you passed rather than an internal temp directory. See the [`kosli attest` reference](/client_reference/kosli_attest_artifact) for usage.
- **`kosli attest` no longer fails on container-produced attachments** — passing two or more `--attachments` paths could abort with `chown ...: operation not permitted` when an attachment (for example lint, test, or coverage output) had been written by a Docker container running as a different user. The CLI no longer tries to preserve file ownership when staging attachments for upload. A genuine copy error now also names the evidence path you passed rather than an internal temp directory. See the [`kosli attest artifact` reference](/client_reference/kosli_attest_artifact) for usage.


[View on GitHub](https://github.com/kosli-dev/cli/releases/tag/v2.36.4)

</Update>

<Update label="July 31, 2026" description="v2.36.3" tags={["CLI"]}>

## Updates
Expand Down
Loading