diff --git a/changelog/index.mdx b/changelog/index.mdx
index bda3b34..7d9c8f8 100644
--- a/changelog/index.mdx
+++ b/changelog/index.mdx
@@ -4,6 +4,50 @@ description: "Release notes for Kosli products."
rss: true
---
+
+
+## Updates
+
+- **Clearer help text for API key expiry** — reworded the `--expires-at` help for [`kosli create api-key`](/client_reference/kosli_create_api-key) and [`kosli rotate api-key`](/client_reference/kosli_rotate_api-key), and the `--grace-period-hours` help, to spell out that keys always expire, that leaving `--expires-at` unset uses the maximum allowed lifetime, and that dates beyond the maximum are capped.
+
+[View on GitHub](https://github.com/kosli-dev/cli/releases/tag/v2.40.1)
+
+
+
+
+
+## Bug fixes
+
+- **`kosli_service_account_api_key` no longer drifts on `expires_at`** — the resource now aligns with the server's 365-day cap on API key expiry, including the "never expires" case, so `expires_at` no longer produces an inconsistent result after apply. Omitting `expires_at` now yields the maximum 365-day expiry rather than a non-expiring key.
+
+[View on GitHub](https://github.com/kosli-dev/terraform-provider-kosli/releases/tag/v0.9.4)
+
+
+
+
+
+## New features
+
+- **`--jira-trailer` on `kosli attest jira`** — read Jira issue keys exclusively from a named git trailer line (for example `Jira: ABC-123`) instead of scanning branch names and commit messages. The flag is mutually exclusive with `--jira-secondary-source`, and `--ignore-branch-match` has no effect when it is set. See the [`kosli attest jira` reference](/client_reference/kosli_attest_jira).
+
+## Updates
+
+- **Pagination for pull request commits and reviews** — GitHub, GitLab, and Azure pull request attestations now page through every commit and every approved review, instead of silently stopping at the provider's default page size (100 for GitHub GraphQL/REST, 20 for GitLab, one page for Azure). A stuck cursor or exhausted page cap now fails the attestation with the pull request named, rather than recording a truncated list. Affects all `kosli attest pullrequest-*` commands.
+- **1 MB payload limit documented** — the help for `--attestation-data` and `--user-data` now states the 1 MB maximum JSON payload size accepted by the server.
+- **Security policy points to the platform bug bounty** — the CLI [SECURITY.md](https://github.com/kosli-dev/cli/blob/main/SECURITY.md) now states that the CLI itself has no bug bounty and directs reporters to the Kosli platform program.
+
+## Bug fixes
+
+- **`kosli.yml` no longer loaded from the working directory** (breaking) — the CLI previously loaded configuration from `kosli.yml` in whichever directory it was invoked in, which let a checked-in file in a repository silently change behavior. It now only reads config from the standard locations. Before upgrading, check for `kosli.yml` files at the root of any repository where the CLI runs.
+- **`kosli snapshot azure` scopes Azure credentials to ACR** — Azure credentials configured for the snapshot are no longer sent to non-Azure Container Registry hosts that a scanned Azure Web App references, closing a credential-disclosure path. See the [`kosli snapshot azure` reference](/client_reference/kosli_snapshot_azure).
+- **`.kosli_ignore` can no longer exclude itself from a fingerprint** — a `.kosli_ignore` entry that matched the file itself used to change the resulting directory fingerprint. The CLI now always includes `.kosli_ignore` when fingerprinting a directory. Directories with self-excluding `.kosli_ignore` files will produce a different fingerprint after upgrading.
+- **`kosli snapshot s3` rejects unsafe object keys** — object keys containing `..` segments are now rejected, and a downloaded object is never overwritten by a later key that resolves to the same local path. Snapshots of buckets with such keys will fail rather than silently collide. See the [`kosli snapshot s3` reference](/client_reference/kosli_snapshot_s3).
+- **`golang.org/x/crypto` upgraded to v0.56.0** — picks up the fix for CVE-2026-56855, a resource-exhaustion issue in `x/crypto/ssh` connection multiplexing.
+
+[View on GitHub](https://github.com/kosli-dev/cli/releases/tag/v2.40.0)
+
+
+
## Updates