Skip to content

Commit e6ff3a0

Browse files
committed
docs: address review comments on August changelog entries
1 parent 26265b8 commit e6ff3a0

1 file changed

Lines changed: 2 additions & 10 deletions

File tree

‎changelog/index.mdx‎

Lines changed: 2 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -21,11 +21,7 @@ rss: true
2121

2222
## New features
2323

24-
- **Custom attestation summaries** — [custom attestation types](/getting_started/attestations) can now define a `summary` list of JQ expressions that extract key values (for example `Critical`, `Tool`) from the payload. The attestation drawer renders these as labelled rows instead of only raw JSON, matching the built-in Sonar, Snyk, and JUnit types. Summaries are versioned with the type, so schema changes create a new version. Array payloads render one summary group per element.
25-
26-
## Updates
27-
28-
- **SCIM changes attributed to "External IdP"** — audit-log rows whose source is `scim` (create, set, or revoke membership) now show **External IdP** in the **Changed by** column instead of the org's first admin. The change is also reflected in the v2 audit-log API, which returns no setter for these rows.
24+
- **Custom attestation summaries** — [custom attestation types](/getting_started/attestations) can now define a `summary` list of JQ expressions that extract key values (for example `Critical`, `Tool`) from the payload. The attestation drawer renders these as labeled rows instead of only raw JSON, matching the built-in Sonar, Snyk, and JUnit types. Summaries are versioned with the type, so schema changes create a new version. Array payloads render one summary group per element.
2925

3026
</Update>
3127

@@ -39,14 +35,10 @@ rss: true
3935

4036
<Update label="August 11, 2026" description="" tags={["Platform"]}>
4137

42-
## Updates
43-
44-
- **SCIM webhook status handling** — a Descope SCIM payload whose status is neither `enabled` nor `disabled` (for example `invited`) is now rejected with an explicit error instead of silently doing nothing. Tenant membership is read from the loaded Descope user, so it always follows authoritative IdP state.
45-
4638
## Bug fixes
4739

4840
- **Faster webhook saves** — the SSRF guard on webhook URLs no longer performs a blocking DNS lookup while saving an action. A slow resolver can no longer stall the save (or time out the request).
49-
- **Notification emails and trail events hardened against injected HTML** — user-controlled names and descriptions in notification emails and trail event descriptions are now HTML-escaped when rendered, closing a defence-in-depth gap on top of existing input validation.
41+
- **Notification emails and trail events hardened against injected HTML** — user-controlled names and descriptions in notification emails and trail event descriptions are now HTML-escaped when rendered, closing a defense-in-depth gap on top of existing input validation.
5042

5143
</Update>
5244

0 commit comments

Comments
 (0)