diff --git a/changelog/index.mdx b/changelog/index.mdx index c5eacc9..77e3628 100644 --- a/changelog/index.mdx +++ b/changelog/index.mdx @@ -4,6 +4,46 @@ description: "Release notes for Kosli products." rss: true --- + + +## Bug fixes + +- **React pages redirect to login on session timeout** — Controls, Repos, Environments, and Audit Log now send you to the login page (with `next` set to where you were) when the session expires, instead of leaving the page with a generic error. +- **Unmatched `/api/*` returns JSON 404** — a request to a non-existent `/api/*` path now returns a JSON `404` instead of redirecting to the HTML login page, so API clients see a proper error. + + + + + +## Bug fixes + +- **Login email field focused on load** — the email input on the login and sign-in pages now receives focus automatically, so you can start typing straight away. +- **No more double-login inside off-canvas panels** — when a session expired while an off-canvas panel was open, the login page could get swapped into the panel instead of taking over the tab. Auth redirects from htmx requests now navigate the whole tab. + + + + + +## Updates + +- **Readable summary for override attestations** — an override attestation now opens on a summary showing the reason, the original attestation's type and status, and a link to the attestation it overrides. The raw JSON payload is still available in the raw view. + +## Bug fixes + +- **Trail-by-artifact lookups no longer fail with tag filters** — `GET /api/v2/trails/{org}` filtered by fingerprint and `flow_tag` could return a 500 on large orgs because the database ran out of memory ordering the query. The fingerprint is now matched before flow filters, so these lookups return normally. + + + + + +## Bug fixes + +- **`kosli attest` no longer fails on container-produced attachments** — passing two or more `--attachments` paths could abort with `chown ...: operation not permitted` when an attachment (for example lint, test, or coverage output) had been written by a Docker container running as a different user. The CLI no longer tries to preserve file ownership when staging attachments for upload. A genuine copy error now also names the evidence path you passed rather than an internal temp directory. See the [`kosli attest artifact` reference](/client_reference/kosli_attest_artifact) for usage. + +[View on GitHub](https://github.com/kosli-dev/cli/releases/tag/v2.36.4) + + + ## Updates